Tanium Threat Response "tanium-tr-alert-update-state" command update all alert status rather than specified alert

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Tanium Threat Response "tanium-tr-alert-update-state" command update all alert status rather than specified alert

L1 Bithead

We are experiencing the weird behavior, where the "tanium-tr-alert-update-state" command update all alert status.

The full command used is as below
!tanium-tr-alert-update-state alert_ids=2267 state=resolved

I have updated the Tanium Threat Response V2 to latest verison 2.0.15

Please help to look into it and let us know what is the solution.

Thank you.

3 REPLIES 3

L2 Linker

can you share a screenshot of the output in the playground after you trigger this command? Thanks

 

Hi Cstone,

 

Attached the screenshot

JOng39_0-1655688323250.png

 

L4 Transporter

Hi @JOng39, I don't see any issue in the code. Looks like its calling the API like the documentation suggests. You might need to check this with your debug logs on Tanium Threat Response UI. 

 

Screen Shot 2022-06-20 at 12.18.40 pm.png

 

You can verify the same using Postman or similar. Refer - https://developer.tanium.com/site/global/docs/how_tos/tr_alert/index.gsp

If this is still an issue after verification, please contact support. 

  • 1586 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!