View as Markdown
Elastic Security icon

Elastic Security ACTION

Update Alert Status

Set the workflow status of one or more Elastic Security alerts (signals) by ID via POST /api/detection_engine/signals/status. Run Search Alerts first to obtain signal IDs. Example: calling with alertStatus: "closed", signalIds: ["abc123"], reason: "false_positive" returns { updated: 1, version_conflicts: 0 }. See the documentation
  • Action
  • Writes data
  • API key
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's Elastic Security account once, then configure and run Update Alert Status from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "elastic_security-update-alert-status",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    elastic_security: { authProvisionId: "apn_xxxxxxx" },
    alertStatus: "Alert Status",
    signalIds: ["Signal IDs"],
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Update Alert Status inputs
Property Type Description
alertStatus Alert Status string
New alert status. One of: open, acknowledged, in-progress, closed. This is the alert's own workflow status, distinct from a case's status.
Required
signalIds Signal IDs string[]
Signal (alert) IDs to update; at least one required. Run Search Alerts first to obtain IDs (the _id field of each hit). Mapped to the API field signal_ids.
Required
reason Reason string
Optional reason for the status change (e.g. false_positive, duplicate, true_positive, benign_positive, automated_closure, other, or a custom string).
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
elastic_security-update-alert-status
Version
0.0.1
App
Elastic Security
Authentication
API key
Read-only
No
Destructive
No
Open world
Yes