unable to add a host group to a sensor update policy #695
-
I'm attempting to add a host group using the uber class. I've tested with both updateSensorUpdatePolicies and the V2 version. Secondly, when I attempt to update a Sensor Update Policy that was created at the parent level, it also has an empty groups item but the CID of that policy gets changed to the client ID. This is visible in the console as it no longer shows "PRECEDENCE
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 5 replies
-
Hi @pk-actzero - Adding a host group will need to be done using the Since we're using the Uber class, we will not have the advantage of body payload abstraction (or from falconpy import APIHarness
falcon = APIHarness(client_id="API_CLIENT_ID_HERE",
client_secret="API_CLIENT_SECRET_HERE"
)
BODY = {
"action_parameters": [
{
"name": "group_id",
"value": "HOST_GROUP_ID_HERE"
}
],
"ids": ['SENSOR_POLICY_ID_HERE']
}
response = falcon.command("performSensorUpdatePoliciesAction", action_name="add-host-group", body=BODY)
print(response)
Regarding the second part of your question, I believe that updating the sensor policy (with an API key that has SensorUpdate:WRITE on the child.) is causing this but I need to recreate and confirm. |
Beta Was this translation helpful? Give feedback.
-
Thanks for the quick response.
presently getting a 500 but I'm wondering if that's because the repo I'm working with has falconpy pegged at <0.9 |
Beta Was this translation helpful? Give feedback.
Hi @pk-actzero -
Adding a host group will need to be done using the
performSensorUpdatePoliciesAction
operation.Since we're using the Uber class, we will not have the advantage of body payload abstraction (or
action_parameter
abstraction) so our syntax will be slightly more complex.