CheckPointHarmonyEndpoint
Checkpoint Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today's complex threat landscape.
Endpoint · Check Point Harmony Endpoint
Details
| ID | CheckPointHarmonyEndpoint |
|---|---|
| Provider | CheckPoint Software Technologies |
| Category | Endpoint |
| From Version | 6.10.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
Checkpoint Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today’s complex threat landscape.
This integration was integrated and tested with version 1 of CheckPointHarmonyEndpoint.
Configure Check Point Harmony Endpoint in Cortex
| Parameter | Required |
|---|---|
| Base URL | True |
| Client ID | True |
| Secret Key | True |
| Trust any certificate (not secure) | False |
| Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
harmony-ep-job-status-get
Retrieves the status and result (if any) of a given asynchronous operation. A job is a way to monitor the progress of an asynchronous operation while avoiding issues that may manifest during long synchronous waits.
Base Command
harmony-ep-job-status-get
Input
| Argument Name | Description | Required |
|---|---|---|
| job_id | The ID of the operation to query the status of. Job ID will returned from most of the commands in this integration. It can be found in the context path. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.Job.data | String | The job data. |
| HarmonyEP.Job.status | String | The job status. |
Command example
#### Context Example
```json
{
"HarmonyEP": {
"Job": {
"data": {
"data": [
{
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"response": null,
"status": "DA_NOT_INSTALLED"
}
},
{
"machine": {
"id": "2",
"name": "DESKTOP-2"
},
"operation": {
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
],
"metadata": {
"count": 2,
"from": 0,
"to": 100
}
},
"status": "DONE",
"statusCode": 200,
"statusType": 2
}
}
}
Human Readable Output
Results
data status statusCode statusType data: {‘machine’: {‘id’: ‘1’, ‘name’: ‘DESKTOP-1’}, ‘operation’: {‘response’: None, ‘status’: ‘DA_NOT_INSTALLED’}},
{‘machine’: {‘id’: ‘2’, ‘name’: ‘DESKTOP-2’}, ‘operation’: {‘response’: None, ‘status’: ‘DA_NOT_INSTALLED’}}
metadata: {“from”: 0, “to”: 100, “count”: 2}DONE 200 2
harmony-ep-ioc-list
Gets a list of all Indicators of Compromise. Use the filter parameters to fetch specific IOCs.
Base Command
harmony-ep-ioc-list
Input
| Argument Name | Description | Required |
|---|---|---|
| filter | The indicator value or comment to search for. The filter is case-insensitive. For example, filter ‘efg will match IoCs ‘abcdEFG’, ‘efGGG’, and ‘yEfG’. | Optional |
| field | The Indicator of Compromise field to search by. Possible values are: iocValue, iocComment. Default is iocValue. | Optional |
| sort_direction | The way to sort the results. Possible values are: ASC, DESC. Default is DESC. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.IOC.comment | String | The IOC comment. |
| HarmonyEP.IOC.modifiedOn | Number | The time the IOC was modified. |
| HarmonyEP.IOC.value | String | The IOC value. |
| HarmonyEP.IOC.type | String | The IOC type. |
| HarmonyEP.IOC.id | String | The IOC ID. |
Command example
#### Context Example
```json
{
"HarmonyEP": {
"IOC": [
{
"comment": "test",
"id": "3",
"modifiedOn": "2024-04-03T09:15:04.182Z",
"type": "Domain",
"value": "test2.com"
},
{
"comment": "comment",
"id": "4",
"modifiedOn": "2024-05-20T13:14:28.290Z",
"type": "Domain",
"value": "test1.com"
}
]
}
}
Human Readable Output
IOC List
Showing page 1.
Current page size: 50.
Id Type Value Comment Modifiedon 3 Domain test2.com test 2024-04-03T09:15:04.182Z 4 Domain test1.com comment 2024-05-20T13:14:28.290Z
harmony-ep-ioc-update
Updates the given Indicators of Compromise with the given parameters.
Base Command
harmony-ep-ioc-update
Input
| Argument Name | Description | Required |
|---|---|---|
| ioc_id | The ID of the IOC to update. Use harmony-ep-ioc-list command to get all IOC IDs. | Required |
| comment | The IOC comment to update. | Required |
| value | The IOC value to update. | Required |
| type | The IOC type to update. Possible values are: Domain, IP, URL, MD5, SHA1. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.IOC.comment | String | The IOC comment. |
| HarmonyEP.IOC.modifiedOn | Number | The time the IOC was modified. |
| HarmonyEP.IOC.value | String | The IOC value. |
| HarmonyEP.IOC.type | String | The IOC type. |
| HarmonyEP.IOC.id | String | The IOC ID. |
Command example
!harmony-ep-ioc-update ioc_id=8 comment=test value=8.8.8.8 type=IP
Context Example
{
"HarmonyEP": {
"IOC": {
"comment": "test",
"id": "8",
"modifiedOn": "2024-06-24T06:44:49.214Z",
"type": "IP",
"value": "8.8.8.8"
}
}
}
Human Readable Output
IOC 8 was updated successfully
Id Type Value Comment Modifiedon 8 IP 8.8.8.8 test 2024-06-24T06:44:49.214Z
harmony-ep-ioc-create
Creates new Indicators of Compromise using the given parameters.
Base Command
harmony-ep-ioc-create
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | The IOC comment. | Required |
| value | The IOC value. For example, 8.8.8.8 for IP or example.com for Domain. | Required |
| type | The IOC type. Possible values are: Domain, IP, URL, MD5, SHA1. | Required |
Context Output
There is no context output for this command.
Command example
!harmony-ep-ioc-create comment=test value=1.1.1.2 type=IP
Human Readable Output
IOC was created successfully.
harmony-ep-ioc-delete
Deletes the given Indicators of Compromise by their ID.
Base Command
harmony-ep-ioc-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| ids | A A comma-separated list of list of IOC IDs to delete. Use harmony-ep-ioc-list command to get all IOC IDs. | Optional |
| delete_all | Whether to delete all IOCs. This action permanently deletes all Indicators of Compromise and cannot be undone. Possible values are: true, false. Default is false. | Optional |
Context Output
There is no context output for this command.
Command example
!harmony-ep-ioc-delete ids=7
Human Readable Output
IOCs 7 was deleted successfully.
harmony-ep-policy-rule-assignments-get
Gets all entities directly assigned to the given rule.
Base Command
harmony-ep-policy-rule-assignments-get
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to get the assignments. Use harmony-ep-rule-metadata-list command to get all rule IDs. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.Rule.Assignments.type | String | The rule assignment type. |
| HarmonyEP.Rule.Assignments.name | String | The rule assignment name. |
| HarmonyEP.Rule.Assignments.id | String | The rule assignment ID. |
Command example
!harmony-ep-policy-rule-assignments-get rule_id=1a2b
Context Example
{
"HarmonyEP": {
"Rule": {
"assignments": [
{
"id": "456",
"name": "ChromeOsLaptops",
"type": "VIRTUAL_GROUP"
}
],
"id": "1a2b"
}
}
}
Human Readable Output
Rule 1a2b assignments
Id Name Type 456 ChromeOsLaptops VIRTUAL_GROUP
harmony-ep-policy-rule-assignments-add
Assigns the specified entities to the given rule. Specified IDs that are already assigned to the rule are ignored.
Base Command
harmony-ep-policy-rule-assignments-add
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to add assignments to. Use harmony-ep-rule-metadata-list command to get all rule IDs. | Required |
| entities_ids | The entity IDs to assign. | Required |
Context Output
There is no context output for this command.
Command example
!harmony-ep-policy-rule-assignments-add rule_id=1a2b entities_ids=000
Human Readable Output
Entities [‘000’] were assigned to rule 1a2b successfully.
harmony-ep-policy-rule-assignments-remove
Removes the specified entities from the given rule’s assignments. Specified IDs that are not assigned to the rule are ignored.
Base Command
harmony-ep-policy-rule-assignments-remove
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to remove assignments from. Use harmony-ep-rule-metadata-list command to get all rule IDs. | Required |
| entities_ids | The entity IDs to remove. | Required |
Context Output
There is no context output for this command.
Command example
!harmony-ep-policy-rule-assignments-remove rule_id=1a2b entities_ids=000
Human Readable Output
Entities [‘000’] were removed from rule 1a2b successfully.
harmony-ep-policy-rule-install
Installs all policies.
Base Command
harmony-ep-policy-rule-install
Input
| Argument Name | Description | Required |
|---|---|---|
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.PolicyRuleInstall.job_id | String | The job ID of the policy installation. |
Command example
!harmony-ep-policy-rule-install job_id=976
Context Example
{
"HarmonyEP": {
"PolicyRuleInstall": {
"job_id": "976"
}
}
}
Human Readable Output
Policy was installed successfully
Job ID: 976
No entries.
harmony-ep-policy-rule-modifications-get
Gets information on modifications to a given rule. (Modifications are the additions or removal of assignments on a rule since it was last installed).
Base Command
harmony-ep-policy-rule-modifications-get
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to get the modifications of. Use harmony-ep-rule-metadata-list command to get all rule IDs. | Required |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.Rule.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.Rule.order | Number | Rule order. |
| HarmonyEP.Rule.isDefaultRule | Boolean | Whether or not the rule is the default. |
| HarmonyEP.Rule.family | String | A family in the rule-base (legacy and unified). |
| HarmonyEP.Rule.connectionState | String | Rule connection state. |
| HarmonyEP.Rule.comment | String | Rule comment. |
| HarmonyEP.Rule.assignments.type | String | Rule assignments type. |
| HarmonyEP.Rule.assignments.name | String | Rule assignments name. |
| HarmonyEP.Rule.assignments.id | String | Rule assignments ID. |
| HarmonyEP.Rule.name | String | Rule name. |
| HarmonyEP.Rule.id | String | Rule ID. |
| HarmonyEP.Rule.orientation | String | Rule policy orientation. |
Command example
!harmony-ep-policy-rule-modifications-get rule_id=1a2b job_id=999
Context Example
{
"HarmonyEP": {
"Rule": {
"connectionState": "CONNECTED",
"family": "Access",
"id": "1a2b",
"job_id": "999",
"lastModifiedBy": "talg",
"lastModifiedOn": {
"iso-8601": "2024-06-24T09:04:43.000Z",
"posix": 1719219883000
},
"modified": {
"assignments": {
"modified": false
},
"order": {
"modified": false
},
"settings": {
"modified": true
}
},
"name": "New Rule 1"
}
}
}
Human Readable Output
Rule 1a2b modification
Job ID: 999
Id Name Family Connectionstate Lastmodifiedby Job Id 1a2b New Rule 1 Access CONNECTED talg 999
harmony-ep-policy-rule-metadata-list
Gets the metadata of all rules or the given rule’s metadata. (Metadata refers to all information relating to the rule except it’s actual settings).
Base Command
harmony-ep-policy-rule-metadata-list
Input
| Argument Name | Description | Required |
|---|---|---|
| rule_id | The ID of the rule to get the metadata. | Optional |
| rule_family | An optional ‘Rule Family’ filter. Used to filter the results to only the selected rule family (e.g., only ‘Threat Prevention’). Possible values are: General Settings, Threat Prevention, Data Protection, OneCheck, Deployment, Remote Access VPN, Capsule Docs, Access, Agent Settings. | Optional |
| connection_state | An optional ‘Connection State’ filter. Used to filter the results to only the selected Connection State (e.g., only rules pertaining to policies for connected clients). Possible values are: CONNECTED, DISCONNECTED, RESTRICTED. | Optional |
| limit | The maximum number of IP lists to return. Default is 50. | Optional |
| all_results | Whether to return all of the results or not. Possible values are: true, false. Default is false. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.Rule.order | Number | Rule order. |
| HarmonyEP.Rule.isDefaultRule | Boolean | Whether or not the rule is the default. |
| HarmonyEP.Rule.family | String | A family in the rule-base (legacy and unified). |
| HarmonyEP.Rule.connectionState | String | Rule connection state. |
| HarmonyEP.Rule.comment | String | Rule comment. |
| HarmonyEP.Rule.assignments.type | String | Rule assignments type. |
| HarmonyEP.Rule.assignments.name | String | Rule assignments name. |
| HarmonyEP.Rule.assignments.id | String | Rule assignments ID. |
| HarmonyEP.Rule.name | String | Rule name. |
| HarmonyEP.Rule.id | String | Rule ID. |
| HarmonyEP.Rule.orientation | String | Rule policy orientation. |
Command example
!harmony-ep-policy-rule-metadata-list rule_id=1a2b
Context Example
{
"HarmonyEP": {
"Rule": {
"assignments": [
{
"id": "000",
"name": "Entire Organization",
"type": "ORGANIZATION_ROOT"
},
{
"id": "456",
"name": "ChromeOsLaptops",
"type": "VIRTUAL_GROUP"
}
],
"comment": "",
"connectionState": "CONNECTED",
"family": "Threat Prevention",
"id": "1a2b",
"isDefaultRule": true,
"name": "TalTest",
"order": 2,
"orientation": "DEVICE"
}
}
}
Human Readable Output
Rule 1a2b metadata
Id Name Family Comment Orientation Connectionstate Assignments 1a2b TalTest Threat Prevention DEVICE CONNECTED {‘id’: ‘000’, ‘name’: ‘Entire Organization’, ‘type’: ‘ORGANIZATION_ROOT’},
{‘id’: ‘456’, ‘name’: ‘ChromeOsLaptops’, ‘type’: ‘VIRTUAL_GROUP’}
harmony-ep-push-operation-status-list
Gets the current statuses of all remediation operations or if a specific ID is specified, retrieve the current status of the given remediation operation.
Base Command
harmony-ep-push-operation-status-list
Input
| Argument Name | Description | Required |
|---|---|---|
| remediation_operation_id | Remediation operations ID. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.PushOperation.adminName | String | The name of the administrator who initiated the operation. |
| HarmonyEP.PushOperation.aborted | Boolean | Indicated whether the operation was aborted by an administrator. |
| HarmonyEP.PushOperation.remainingTimeoutSeconds | Number | The amount of time, in seconds, the operation will remain active. When elapsed, no more entities will be affected. |
| HarmonyEP.PushOperation.createdOn | Date | The date and time the operation was created. |
| HarmonyEP.PushOperation.type | String | Remediation operation type. |
| HarmonyEP.PushOperation.comment | String | A comment that was provided during the operation’s creation. |
| HarmonyEP.PushOperation.id | String | The operation’s ID. |
| HarmonyEP.PushOperation.overallStatus | String | Remediation operation status. |
| HarmonyEP.PushOperation.numberOfAffectedEntities | Number | The total number of entities affected by the operation. |
Command example
!harmony-ep-push-operation-status-list remediation_operation_id=4d
Context Example
{
"HarmonyEP": {
"PushOperation": {
"aborted": true,
"adminName": "talg",
"createdOn": "2024-06-20T10:58:19.407Z",
"id": "d45",
"job_id": "3",
"numberOfAffectedEntities": 6,
"operationParameters": {
"allowPostpone": false,
"informUser": true,
"originalTimeoutSeconds": 86400,
"schedulingType": "IMMEDIATE"
},
"overallStatus": "ABORTED",
"remainingTimeoutSeconds": 0,
"type": "AM_SCAN"
}
}
}
Human Readable Output
Push operations status list
Job ID: 3
Id Type Createdon Overallstatus d45 AM_SCAN 2024-06-20T10:58:19.407Z ABORTED
harmony-ep-push-operation-get
Gets the results of a given Remediation Operation. Remediation Operations may produce results such a Forensics Report or yield status updates such as an anti-malware scan progress.
Base Command
harmony-ep-push-operation-get
Input
| Argument Name | Description | Required |
|---|---|---|
| remediation_operation_id | Remediation operation ID. Use the harmony-ep-remediation-status-list command to get all remediation operation IDs. | Required |
| filter_text | Optional free text search in any of the potential response fields excluding “id”. Can be used to search for specific results, devices or IPs, for example. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-push-operation-get remediation_operation_id=4d
Context Example
{
"HarmonyEP": {
"PushOperation": [
{
"job_id": "6",
"machine": {
"id": "5s",
"name": "DESKTOP-M4OAKII"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
Human Readable Output
Push operations
Job ID: 6
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 5s DESKTOP-M4OAKII DA_NOT_INSTALLED
harmony-ep-push-operation-abort
Aborts the given remediation operation. Aborting an operation prevents it from being sent to further Harmony Endpoint Clients. Clients that have already received the operation are not affected.
Base Command
harmony-ep-push-operation-abort
Input
| Argument Name | Description | Required |
|---|---|---|
| remediation_operation_id | Remediation operation ID. Use the harmony-ep-remediation-status-list command to get all remediation operation IDs. | Required |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.PushOperationAbort.job_id | String | The job ID of the remediation operation. |
Command example
!harmony-ep-push-operation-abort remediation_operation_id=93 job_id=976
Context Example
{
"HarmonyEP": {
"PushOperationAbort": {
"job_id": "976"
}
}
}
Human Readable Output
Remediation operation abort was added to the push operation list successfully
Job ID: 976
No entries.
harmony-ep-anti-malware-scan
Performs an anti-malware scan on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-anti-malware-scan
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.AntiMalwareScan.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.AntiMalwareScan.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.AntiMalwareScan.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.AntiMalwareScan.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.AntiMalwareScan.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.AntiMalwareScan.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.AntiMalwareScan.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.AntiMalwareScan.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-anti-malware-scan computer_ids=1
Context Example
{
"HarmonyEP": {
"AntiMalwareScan": {
"PushOperation": [
{
"job_id": "13",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Anti-Malware scan was added to the push operation list successfully
Job ID: 13
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-anti-malware-update
Updates the anti-malware Signature Database on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-anti-malware-update
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| update_from_ep_server | Determines whether to update from the EP server. Possible values are: true, false. Default is false. | Optional |
| update_from_cp_server | Determines whether to update from the CP server. Possible values are: true, false. Default is false. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.AntiMalwareUpdate.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.AntiMalwareUpdate.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-anti-malware-update computer_ids=1
Context Example
{
"HarmonyEP": {
"AntiMalwareUpdate": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Anti-Malware Signature Database update was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-anti-malware-restore
Restores a file that was previously quarantined by the Harmony Endpoint Client’s anti-malware capability. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-anti-malware-restore
Input
| Argument Name | Description | Required |
|---|---|---|
| files | A list of file paths to restore. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.AntiMalwareRestore.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.AntiMalwareRestore.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.AntiMalwareRestore.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.AntiMalwareRestore.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.AntiMalwareRestore.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.AntiMalwareRestore.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.AntiMalwareRestore.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.AntiMalwareRestore.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-anti-malware-restore files=test computer_ids=1
Context Example
{
"HarmonyEP": {
"AntiMalwareRestore": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
File restore was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-forensics-indicator-analyze
Collects forensics data whenever a computer that matches the given query accesses or executes the given IP, URL, filename, MD5 or path. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-forensics-indicator-analyze
Input
| Argument Name | Description | Required |
|---|---|---|
| indicator_type | The indictor type to analyze. Possible values are: IP, URL, File, MD5, Path. | Required |
| indicator_value | A URL, IP, Path, File or MD5 that when accessed or executed will trigger a forensics report. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| generate_activity_logs | Determines whether to generate detailed activity logs. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.IndicatorAnalyze.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.IndicatorAnalyze.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.IndicatorAnalyze.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.IndicatorAnalyze.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.IndicatorAnalyze.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.IndicatorAnalyze.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.IndicatorAnalyze.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.IndicatorAnalyze.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-forensics-indicator-analyze indicator_type=IP indicator_value=8.8.8.8 computer_ids=1
Context Example
{
"HarmonyEP": {
"IndicatorAnalyze": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
IOC analyze was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-forensics-file-quarantine
Quarantines files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-forensics-file-quarantine
Input
| Argument Name | Description | Required |
|---|---|---|
| file_type | The forensics quarantine item type. Possible values are: PATH, INCIDENT_ID, MD5. | Required |
| file_value | The forensics quarantine item value. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.FileQuarantine.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.FileQuarantine.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.FileQuarantine.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.FileQuarantine.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.FileQuarantine.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.FileQuarantine.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.FileQuarantine.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.FileQuarantine.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-forensics-file-quarantine file_type=PATH file_value=test computer_ids=1
Context Example
{
"HarmonyEP": {
"FileQuarantine": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
File quarantine was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-forensics-file-restore
Restores previously quarantined files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-forensics-file-restore
Input
| Argument Name | Description | Required |
|---|---|---|
| file_type | The forensics quarantine item type. Possible values are: PATH, INCIDENT_ID, MD5. | Required |
| file_value | The forensics quarantine item value. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.FileRestore.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.FileRestore.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.FileRestore.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.FileRestore.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.FileRestore.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.FileRestore.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.FileRestore.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.FileRestore.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-forensics-file-restore file_type=PATH file_value=test computer_ids=1
Context Example
{
"HarmonyEP": {
"FileRestore": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
File restore was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-remediation-computer-isolate
Isolates the computers matching the given query. Isolation is the act of denying all network access from a given computer. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-remediation-computer-isolate
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ComputerIsolate.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ComputerIsolate.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ComputerIsolate.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ComputerIsolate.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ComputerIsolate.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ComputerIsolate.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ComputerIsolate.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ComputerIsolate.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-remediation-computer-isolate computer_ids=1
Context Example
{
"HarmonyEP": {
"ComputerIsolate": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Remediation isolate was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-remediation-computer-deisolate
De-Isolates the computers matching the given query. De-isolating a computer restores its access to network resources. Affects only isolated computers. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-remediation-computer-deisolate
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ComputerDeisolate.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ComputerDeisolate.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ComputerDeisolate.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ComputerDeisolate.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ComputerDeisolate.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ComputerDeisolate.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ComputerDeisolate.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ComputerDeisolate.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-remediation-computer-deisolate computer_ids=1
Context Example
{
"HarmonyEP": {
"ComputerDeisolate": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Remediation de-isolate was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-computer-restart
Restarts computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-computer-restart
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| force_apps_shutdown | Determines whether to force applications shutdown. Possible values are: true, false. Default is false. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ComputerRestart.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ComputerRestart.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ComputerRestart.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ComputerRestart.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ComputerRestart.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ComputerRestart.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ComputerRestart.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ComputerRestart.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-computer-restart computer_ids=1
Context Example
{
"HarmonyEP": {
"ComputerReset": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Computer reset restore was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-computer-shutdown
Shuts-down computers match the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-computer-shutdown
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| force_apps_shutdown | Determines whether to force applications shutdown. Possible values are: true, false. Default is false. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ComputerShutdown.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ComputerShutdown.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ComputerShutdown.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ComputerShutdown.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ComputerShutdown.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ComputerShutdown.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ComputerShutdown.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ComputerShutdown.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-computer-shutdown computer_ids=1
Context Example
{
"HarmonyEP": {
"ComputerShutdown": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Computer shutdown was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-computer-repair
Repairs the Harmony Endpoint Client installation on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-computer-repair
Input
| Argument Name | Description | Required |
|---|---|---|
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ComputerRepair.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ComputerRepair.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ComputerRepair.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ComputerRepair.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ComputerRepair.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ComputerRepair.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ComputerRepair.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ComputerRepair.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-computer-repair computer_ids=1
Context Example
{
"HarmonyEP": {
"ComputerRepair": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Computer repair was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-computer-list
Gets a list of computers matching the given filters. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-computer-list
Input
| Argument Name | Description | Required |
|---|---|---|
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.Computer.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.Computer.CapabilitiesInstalled | String | A list of all installed capabilities. |
| HarmonyEP.Computer.InstalledAndRunning | String | A list of installed and running capabilities. |
| HarmonyEP.Computer.ClientVersion | String | The computer client version. |
| HarmonyEP.Computer.DeployTime | String | The computer deploy time. |
| HarmonyEP.Computer.Groups | String | The computer groups. |
| HarmonyEP.Computer.type | String | The computer type. |
| HarmonyEP.Computer.userName | String | The computer user name. |
| HarmonyEP.Computer.domainName | String | The computer domain name. |
| HarmonyEP.Computer.isolationStatus | String | The computer isolation status. |
| HarmonyEP.Computer.ClientVersion | String | The computer client veraion. |
| HarmonyEP.Computer.LastLoggedInUser | String | The computer last login user. |
| HarmonyEP.Computer.osName | String | The computer operating system name. |
| HarmonyEP.Computer.osVersion | String | The computer operating system version. |
| HarmonyEP.Computer.ip | String | The computer IP address. |
| HarmonyEP.Computer.DeploymentStatus | String | The computer deployment status. |
| HarmonyEP.Computer.name | String | The computer name. |
| HarmonyEP.Computer.id | String | The computer’s unique ID. |
Command example
!harmony-ep-computer-list computer_ids=1 job_id=845
Context Example
{
"HarmonyEP": {
"Computer": {
"Computer": [
{
"client_version": "87.62.2002",
"deployment_status": "Completed",
"domain_name": ".WORKGROUP",
"groups": [
{
"id": "666",
"name": "Desktops"
},
{
"id": "222",
"name": "WinDesktops"
}
],
"id": "888",
"ip": "1.1.1.1",
"isolation_status": "Not Isolated",
"last_logged_in_user": "ntlocal",
"name": "DESKTOP-E7V07D5",
"os_name": "Microsoft Windows 10 Pro",
"os_version": "10.0-19045-SP0.0-SMP",
"type": "Desktop",
"user_name": "ntlocal"
}
],
"job_id": "845"
}
}
}
Human Readable Output
Computer list
Job ID: 845
Showing page 1.
Current page size: 50.
Id Name Ip Type Groups User Name Client Version 888 DESKTOP-E7V07D5 1.1.1.1 Desktop {‘id’: ‘666’, ‘name’: ‘Desktops’},
{‘id’: ‘222’, ‘name’: ‘WinDesktops’}ntlocal 87.62.2002
harmony-ep-agent-process-information-get
Collects information about processes on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-process-information-get
Input
| Argument Name | Description | Required |
|---|---|---|
| process_name | The name of the process to collect information on. If not provided, all running processes will be collected. | Optional |
| additional_fields | Additional process properties to collect. If not provided, only the process’s name and ID will be collected. Possible values are: SI, Handles, VM, WS, PM, NPM, Path, CPU, ExitCode, ExitTime, Handle, HandleCount, HasExited, Id, MachineName, MainModule, MainWindowHandle, MainWindowTitle, MaxWorkingSet, MinWorkingSet, Modules, NonpagedSystemMemorySize, NonpagedSystemMemorySize64, PagedMemorySize, PagedMemorySize64, PagedSystemMemorySize, PagedSystemMemorySize64, PeakPagedMemorySize, PeakPagedMemorySize64, PeakVirtualMemorySize, PeakVirtualMemorySize64, PeakWorkingSet, PeakWorkingSet64, PriorityBoostEnabled, PriorityClass, PrivateMemorySize, PrivateMemorySize64, PrivilegedProcessorTime, ProcessName, ProcessorAffinity, Responding, SafeHandle, SessionId, StandardError, StandardInput, StandardOutput, StartInfo, StartTime, SynchronizingObject, Threads, TotalProcessorTime, UserProcessorTime, VirtualMemorySize, VirtualMemorySize64, WorkingSet, WorkingSet64. | Optional |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ProcessInformation.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ProcessInformation.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ProcessInformation.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ProcessInformation.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ProcessInformation.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ProcessInformation.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ProcessInformation.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ProcessInformation.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-process-information-get computer_ids=1
Context Example
{
"HarmonyEP": {
"ProcessInformation": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Process information fetch was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-process-terminate
Terminates the given process on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-process-terminate
Input
| Argument Name | Description | Required |
|---|---|---|
| terminate_all_instances | Indicates whether to terminate all processes matching the given name. If set to true while a non-zero PID is given, only a single process with the given name AND PID may be matched. If set to false or not provided, will terminate only the first matching process. Possible values are: true, false. Default is false. | Optional |
| name | The name of the process to terminate. | Required |
| pid | The ID (PID) of the process to terminate. When used in conjunction with the name field, the PID must match the named process. If both name and PID are provided but the process matching the PID does not match the provided name, the operation will be ignored by the agent. If set to 0 or not provided, the agent will seek to terminate the process or processes as indicated by the name field. | Optional |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.ProcessTerminate.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.ProcessTerminate.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.ProcessTerminate.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.ProcessTerminate.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.ProcessTerminate.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.ProcessTerminate.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.ProcessTerminate.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.ProcessTerminate.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-process-terminate name=test computer_ids=1
Context Example
{
"HarmonyEP": {
"ProcessTerminate": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
Process terminate was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-registry-key-add
Adds a given registry key and/or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-registry-key-add
Input
| Argument Name | Description | Required |
|---|---|---|
| is_redirected | Determines if the key should reside under WOW6432Node. Keys intended for 64bit versions of Windows may target 32bit versions by setting this value to ‘true, thus specifying that the registry key/value be added under the WOW6432Node. Possible values are: true, false. | Optional |
| value_data | The actual value to be added the the specified registry key. | Required |
| value_type | A registry value’s type. Possible values are: DWORD (REG_DWORD), STRING (REG_GZ). | Required |
| value_name | The name of the value to be added to the specified registry key. | Required |
| key | The full path path of the key to create or add a value to. For example, ‘SOFTWARE\Node.js\Components’. | Required |
| hive | Defines known Windows Registry Hives. For more information, see https://docs.microsoft.com/en-us/windows/win32/sysinfo/predefined-keys. Possible values are: HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT, HKEY_USERS, HKEY_CURRENT_CONFIG. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.RegistryKeyAdd.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.RegistryKeyAdd.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.RegistryKeyAdd.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.RegistryKeyAdd.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.RegistryKeyAdd.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.RegistryKeyAdd.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.RegistryKeyAdd.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.RegistryKeyAdd.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-registry-key-add value_data=test value_type="STRING (REG_GZ)" value_name=test key=test hive=HKEY_USERS computer_ids=1
Context Example
{
"HarmonyEP": {
"RegistryKeyAdd": {
"PushOperation": {
"job_id": "54",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": "88",
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
}
}
}
Human Readable Output
Registry key add was added to the push operation list successfully
Job ID: 54
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-registry-key-delete
Removes the given registry key or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-registry-key-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| is_redirected | Determines if the key should be removed from under WOW6432Node. Keys intended for 64bit versions of Windows may target 32bit versions by setting this value to ‘true’, thus specifying that the registry key/value be removed under the WOW6432Node. Possible values are: true, false. | Optional |
| value_name | The value to remove from the key. If not provided, the entire key will be deleted. | Optional |
| key | The full path path of the key to delete or remove a value from. For example, ‘SOFTWARE\Node.js\Components’. | Required |
| hive | Defines known Windows Registry Hives. For more information, see https://docs.microsoft.com/en-us/windows/win32/sysinfo/predefined-keys. Possible values are: HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT, HKEY_USERS, HKEY_CURRENT_CONFIG. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.RegistryKeyDelete.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.RegistryKeyDelete.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.RegistryKeyDelete.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.RegistryKeyDelete.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.RegistryKeyDelete.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.RegistryKeyDelete.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.RegistryKeyDelete.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.RegistryKeyDelete.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-registry-key-delete value_name='test' key='test' hive=HKEY_USERS computer_ids=1
Context Example
{
"HarmonyEP": {
"RegistryKeyDelete": {
"PushOperation": {
"job_id": "54",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": "88",
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
}
}
}
Human Readable Output
Registry key delete was added to the push operation list successfully
Job ID: 54
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-file-copy
Copies the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-file-copy
Input
| Argument Name | Description | Required |
|---|---|---|
| destination_absolute_path | The absolute, full destination path. The provided path must include the target file’s name (e.g., c:\backup\backup1.txt). | Required |
| source_absolute_path | The absolute, full source path (e.g., c:\backup\backup1.txt). | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.FileCopy.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.FileCopy.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.FileCopy.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.FileCopy.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.FileCopy.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.FileCopy.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.FileCopy.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.FileCopy.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-file-copy destination_absolute_path='test.txt' source_absolute_path='test.txt' computer_ids=1
Context Example
{
"HarmonyEP": {
"FileCopy": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
File copy was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-file-move
Moves the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-file-move
Input
| Argument Name | Description | Required |
|---|---|---|
| destination_absolute_path | The absolute, full destination path. The provided path must include the target file’s name (e.g., c:\backup\backup1.txt). | Required |
| source_absolute_path | The absolute, full source path (e.g., c:\backup\backup1.txt). | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.FileMove.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.FileMove.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.FileMove.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.FileMove.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.FileMove.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.FileMove.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.FileMove.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.FileMove.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-file-move destination_absolute_path='test.txt' source_absolute_path='test.txt' computer_ids=1
Context Example
{
"HarmonyEP": {
"FileMove": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
Human Readable Output
File move was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-file-delete
Deletes the given file from the given source on computers matching the given query. This operation is risky! Use with caution as it allows you to change Harmony Endpoint protected files or registry entries that are in use by your operating system. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-file-delete
Input
| Argument Name | Description | Required |
|---|---|---|
| target_absolute_path | The absolute, full path of the file to remove. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.FileDelete.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.FileDelete.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.FileDelete.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.FileDelete.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.FileDelete.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.FileDelete.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.FileDelete.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.FileDelete.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-file-delete target_absolute_path='test.txt' computer_ids=1
Context Example
{
"HarmonyEP": {
"FileDelete": {
"PushOperation": [
{
"job_id": "16",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": null,
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
]
}
}
}
Human Readable Output
File delete was added to the push operation list successfully
Job ID: 16
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-vpn-site-add
Adds the given VPN site’s configuration to computers matching the given query. Adding a VPN site allows Harmony Endpoint Clients to connect to it. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-vpn-site-add
Input
| Argument Name | Description | Required |
|---|---|---|
| remote_access_gateway_name | The remote gateway’s name. | Required |
| fingerprint | The remote gateway’s certificate fingerprint. Fingerprints are used to verify the authenticity of the gateway. | Required |
| authentication_method | Authentication methods used in conjunction with VPN site standard login. Possible values are: CERTIFICATE, P12_CERTIFICATE, USERNAME_PASSWORD, SECURID_KEY_FOB, SECURID_PIN_PAD, SOFTID, CHALLENGE_RESPONSE. | Required |
| display_name | The VPN site’s display name. | Optional |
| host | The target site’s host name or IP address. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-vpn-site-add remote_access_gateway_name='test' fingerprint='test' authentication_method=CERTIFICATE host='test' computer_ids=1
Context Example
{
"HarmonyEP": {
"VPNsiteConfigurationAdd": {
"PushOperation": {
"job_id": "67",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": "23",
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
}
}
}
Human Readable Output
VPN site configuration remove was added to the push operation list successfully
Job ID: 67
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
harmony-ep-agent-vpn-site-remove
Removes the given VPN site’s configuration to computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
Base Command
harmony-ep-agent-vpn-site-remove
Input
| Argument Name | Description | Required |
|---|---|---|
| display_name | The display name of the VPN site to remove. If a display name was not provided during the site’s creation, the host name/IP should be used instead. | Required |
| comment | Operation comment. | Optional |
| scheduling_date_time | Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. | Optional |
| expiration_seconds | The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. | Optional |
| computer_ids | A comma-separated list of computer IDs to include in the operation. | Optional |
| computer_names | A comma-separated list of computer names to include in the operation. | Optional |
| computer_ips | A comma-separated list of computer IPs to include in the operation. | Optional |
| computer_types | A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. | Optional |
| computer_deployment_statuses | A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. | Optional |
| computer_last_connection | Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. | Optional |
| filter | A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . | Optional |
| groups_ids_to_exclude | A comma-separated list of group IDs to exclude from the operation. | Optional |
| computers_ids_to_exclude | A comma-separated list of computer IDs to exclude from the operation. | Optional |
| computers_ids_to_include | A comma-separated list of computer IDs to include in the operation. | Optional |
| inform_user | Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. | Optional |
| allow_postpone | Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. | Optional |
| page | Page number of paginated results. Minimum value: 1. | Optional |
| page_size | The number of items per page. | Optional |
| limit | The maximum number of records to retrieve. Default is 50. | Optional |
| interval | The interval between each poll in seconds. Minimum value is 10. Default is 30. |
Optional |
| timeout | The timeout for the polling in seconds. Default is 600. | Optional |
| job_id | The job ID to fetch data for. Hidden argument. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.job_id | String | The job ID of the remediation operation. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.id | String | The remediation operation ID. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.status | String | Describes possible states in which a push operation may be in regards to a specific device. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.response.status | String | Push operation response status. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.response.output | String | Push operation response output. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.ipAddress | String | The client device’s IPv4 address. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.name | String | The client device’s name. |
| HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.id | String | The client device’s unique ID. |
Command example
!harmony-ep-agent-vpn-site-remove display_name='test' computer_ids=1
Context Example
{
"HarmonyEP": {
"VPNsiteConfigurationRemove": {
"PushOperation": {
"job_id": "67",
"machine": {
"id": "1",
"name": "DESKTOP-1"
},
"operation": {
"id": "23",
"response": null,
"status": "DA_NOT_INSTALLED"
}
}
}
}
}
Human Readable Output
VPN site configuration remove was added to the push operation list successfully
Job ID: 67
Showing page 1.
Current page size: 50.
Machine Id Machine Name Operation Status 1 DESKTOP-1 DA_NOT_INSTALLED
Configuration parameters
base_url— Base URL (required)credentials— Client ID (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (35)
-
harmony-ep-agent-computer-repairRepairs the Harmony Endpoint Client installation on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-computer-restartRestarts computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-computer-shutdownShuts-down computers match the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-file-copyCopies the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-file-deleteDeletes the given file from the given source on computers matching the given query. This operation is risky! Use with caution as it allows you to change Harmony Endpoint protected files or registry entries that are in use by your operating system. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-file-moveMoves the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-process-information-getCollects information about processes on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-process-terminateTerminates the given process on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-registry-key-addAdds a given registry key and/or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-registry-key-deleteRemoves the given registry key or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-vpn-site-addAdds the given VPN site's configuration to computers matching the given query. Adding a VPN site allows Harmony Endpoint Clients to connect to it. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-agent-vpn-site-removeRemoves the given VPN site's configuration to computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-anti-malware-restoreRestores a file that was previously quarantined by the Harmony Endpoint Client's anti-malware capability. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-anti-malware-scanPerforms an anti-malware scan on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-anti-malware-updateUpdates the anti-malware Signature Database on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-computer-listGets a list of computers matching the given filters. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-forensics-file-quarantineQuarantines files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-forensics-file-restoreRestores previously quarantined files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-forensics-indicator-analyzeCollects forensics data whenever a computer that matches the given query accesses or executes the given IP, URL, filename, MD5 or path. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-ioc-createCreates new Indicators of Compromise using the given parameters.
-
harmony-ep-ioc-deleteDeletes the given Indicators of Compromise by their ID.
-
harmony-ep-ioc-listGets a list of all Indicators of Compromise. Use the filter parameters to fetch specific IOCs.
-
harmony-ep-ioc-updateUpdates the given Indicators of Compromise with the given parameters.
-
harmony-ep-job-status-getRetrieves the status and result (if any) of a given asynchronous operation. A job is a way to monitor the progress of an asynchronous operation while avoiding issues that may manifest during long synchronous waits.
-
harmony-ep-policy-rule-assignments-addAssigns the specified entities to the given rule. Specified IDs that are already assigned to the rule are ignored.
-
harmony-ep-policy-rule-assignments-getGets all entities directly assigned to the given rule.
-
harmony-ep-policy-rule-assignments-removeRemoves the specified entities from the given rule's assignments. Specified IDs that are not assigned to the rule are ignored.
-
harmony-ep-policy-rule-installInstalls all policies.
-
harmony-ep-policy-rule-metadata-listGets the metadata of all rules or the given rule's metadata. (Metadata refers to all information relating to the rule except it's actual settings).
-
harmony-ep-policy-rule-modifications-getGets information on modifications to a given rule. (Modifications are the additions or removal of assignments on a rule since it was last installed).
-
harmony-ep-push-operation-abortAborts the given remediation operation. Aborting an operation prevents it from being sent to further Harmony Endpoint Clients. Clients that have already received the operation are not affected.
-
harmony-ep-push-operation-getGets the results of a given Remediation Operation. Remediation Operations may produce results such a Forensics Report or yield status updates such as an anti-malware scan progress.
-
harmony-ep-push-operation-status-listGets the current statuses of all remediation operations or if a specific ID is specified, retrieve the current status of the given remediation operation.
-
harmony-ep-remediation-computer-deisolateDe-Isolates the computers matching the given query. De-isolating a computer restores its access to network resources. Affects only isolated computers. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
-
harmony-ep-remediation-computer-isolateIsolates the computers matching the given query. Isolation is the act of denying all network access from a given computer. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.
import json import os import unittest.mock from collections.abc import Callable from typing import Any import CheckPointHarmonyEndpoint import CommonServerPython import pytest TEST_DATA = "test_data" BASE_URL = "https://www.example.com/" API_URL = CommonServerPython.urljoin(BASE_URL, "app/endpoint-web-mgmt/harmony/endpoint/api/v1") def load_mock_response(file_name: str) -> dict[str, Any] | list[dict[str, Any]]: """Load mock file that simulates an API response. Args: file_name (str): Name of the mock response JSON file to return. Returns: dict[str, Any]: Mock file content. """ file_path = os.path.join(TEST_DATA, file_name) with open(file_path, encoding="utf-8") as mock_file: return json.loads(mock_file.read()) @pytest.fixture() def mock_client() -> CheckPointHarmonyEndpoint.Client: """ Establish a mock connection to the client with a user name and password. Returns: Client: Mock connection to client. """ return CheckPointHarmonyEndpoint.Client( base_url=API_URL, client_id="test", client_secret="test", verify_certificate=False, proxy=False, ) @pytest.mark.parametrize( "command_args, endpoint, response_file", [ ( {"job_id": "123"}, "jobs/123", "job_status.json", ), ], ) def test_job_status_get_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_args: dict[str, Any], endpoint: str, response_file: str, ): """ Scenario: - Test retrieving job status. Given: - Arguments for retrieving job status. When: - Executing job_status_get_command function. Then: - Ensure that the CommandResults outputs is correct. - Ensure that the CommandResults raw_response is correct. - Ensure that the CommandResults outputs_prefix is correct. - Ensure that the CommandResults outputs_key_field is correct. """ mock_response = load_mock_response(response_file) requests_mock.get( url=f"{API_URL}/{endpoint}", json=mock_response, ) command_results = CheckPointHarmonyEndpoint.job_status_get_command(command_args, mock_client) assert command_results.raw_response == mock_response assert command_results.outputs == mock_response assert command_results.outputs_prefix == "HarmonyEP.Job" assert command_results.outputs_key_field == "id" @pytest.mark.parametrize( "command_args, endpoint, response_file", [ ( { "filter": "com", "sort_field": "iocValue", "sort_direction": "ASC", }, "ioc/get", "ioc_list.json", ), ], ) def test_ioc_list_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_args: dict[str, Any], endpoint: str, response_file: str, ): """ Scenario: - Test listing IOCs. Given: - Arguments for listing IOCs. When: - Executing ioc_list_command function. Then: - Ensure that the CommandResults outputs is correct. - Ensure that the CommandResults raw_response is correct. - Ensure that the CommandResults outputs_prefix is correct. - Ensure that the CommandResults outputs_key_field is correct. """ mock_response = load_mock_response(response_file) requests_mock.post( url=f"{API_URL}/{endpoint}", json=mock_response, ) command_results = CheckPointHarmonyEndpoint.ioc_list_command(command_args, mock_client) mock_response["content"][0]["modifiedOn"] = CheckPointHarmonyEndpoint.convert_unix_to_date_string( mock_response["content"][0]["modifiedOn"] ) assert command_results.raw_response == mock_response assert command_results.outputs == mock_response["content"] assert command_results.outputs_prefix == "HarmonyEP.IOC" assert command_results.outputs_key_field == "id" @pytest.mark.parametrize( "command_args, response_file", [ ( { "type": "Domain", "value": "tal.com", "comment": "Tal Domain Test", "ioc_id": "1108", }, "ioc_update.json", ), ], ) def test_ioc_update_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_args: dict[str, Any], response_file: str, ): """ Scenario: - Test updating an IOC. Given: - Arguments for updating an IOC. When: - Executing ioc_update_command function. Then: - Ensure that the CommandResults readable_output is correct. - Ensure that the CommandResults raw_response is correct. - Ensure that the CommandResults outputs_prefix is correct. - Ensure that the CommandResults outputs_key_field is correct. """ mock_response = load_mock_response(response_file) requests_mock.put( url=f"{API_URL}/ioc/edit", json=mock_response, ) command_results = CheckPointHarmonyEndpoint.ioc_update_command(command_args, mock_client) assert command_results.raw_response == mock_response assert command_results.outputs == mock_response assert command_results.outputs_prefix == "HarmonyEP.IOC" assert command_results.outputs_key_field == "id" def test_ioc_create_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, ): """ Scenario: - Test creating an IOC. Given: - Arguments for creating an IOC. When: - Executing ioc_create_command function. Then: - Ensure that the CommandResults readable_output is correct. """ requests_mock.post( url=f"{API_URL}/ioc/create", json="", ) command_results = CheckPointHarmonyEndpoint.ioc_create_command( {"type": "Domain", "value": "example.com", "comment": "Suspicious domain"}, mock_client, ) assert command_results.readable_output == "IOC was created successfully." @pytest.mark.parametrize( "command_args, endpoint, response_file, readable_output", [ ( {"ids": [1, 2, 3], "delete_all": False}, "ioc/delete?ids=%5B1,%202,%203%5D", "ioc_delete.json", "IOCs [1, 2, 3] was deleted successfully.", ), ( {"ids": None, "delete_all": True}, "ioc/delete/all", "ioc_delete.json", "All IOCs were deleted successfully.", ), ], ) def test_ioc_delete_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_args: dict[str, Any], endpoint: str, response_file: str, readable_output: str, ): """ Scenario: - Test deleting an IOC. Given: - Arguments for deleting an IOC. When: - Executing ioc_delete_command function. Then: - Ensure that the CommandResults readable_output is correct. """ mock_response = load_mock_response(response_file) requests_mock.delete( url=f"{API_URL}/{endpoint}", json=mock_response, ) command_results = CheckPointHarmonyEndpoint.ioc_delete_command(command_args, mock_client) assert command_results.readable_output == readable_output def test_rule_assignments_get_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, ): """ Scenario: - Test getting rule assignments. Given: - Arguments for getting rule assignments. When: - Executing rule_assignments_get_command function. Then: - Ensure that the CommandResults readable_output is correct. """ mock_response = load_mock_response("rule_assignments.json") requests_mock.get( url=f"{API_URL}/policy/1/assignments", json=mock_response, ) output = {"id": 1, "assignments": mock_response} command_results = CheckPointHarmonyEndpoint.rule_assignments_get_command({"rule_id": 1}, mock_client) assert command_results.outputs_prefix == "HarmonyEP.Rule" assert command_results.outputs_key_field == "id" assert command_results.raw_response == mock_response assert command_results.outputs == output def test_rule_assignments_add_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, ): """ Scenario: - Test adding rule assignments. Given: - Arguments for adding rule assignments. When: - Executing rule_assignments_add_command function. Then: - Ensure that the CommandResults readable_output is correct. """ requests_mock.put( url=f"{API_URL}/policy/1/assignments/add", json="", ) command_results = CheckPointHarmonyEndpoint.rule_assignments_add_command( {"rule_id": 1, "entities_ids": ["3", "4"]}, mock_client ) assert command_results.readable_output == "Entities ['3', '4'] were assigned to rule 1 successfully." def test_rule_assignments_remove_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, ): """ Scenario: - Test removing rule assignments. Given: - Arguments for removing rule assignments. When: - Executing rule_assignments_remove_command function. Then: - Ensure that the CommandResults readable_output is correct. """ requests_mock.put( url=f"{API_URL}/policy/1/assignments/remove", json="", ) command_results = CheckPointHarmonyEndpoint.rule_assignments_remove_command( {"rule_id": 1, "entities_ids": ["3", "4"]}, mock_client ) assert command_results.readable_output == "Entities ['3', '4'] were removed from rule 1 successfully." @pytest.mark.parametrize( "command_args, endpoint, response_file", [ ( {"limit": 2, "all_results": False}, "policy/metadata", "rule_metadata_list.json", ), ( {"rule_id": 1, "all_results": True}, "policy/1/metadata", "rule_metadata_get.json", ), ], ) def test_rule_metadata_list_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_args: dict[str, Any], endpoint: str, response_file: str, ): """ Scenario: - Test the rule_metadata_list_command function. Given: - Arguments for the command. When: - Executing the rule_metadata_list_command function. Then: - Ensure that the CommandResults are as expected. """ mock_response: dict[str, Any] | list[dict[str, Any]] = load_mock_response(response_file) requests_mock.get( url=f"{API_URL}/{endpoint}", json=mock_response, ) command_results = CheckPointHarmonyEndpoint.rule_metadata_list_command(command_args, mock_client) mock_response = mock_response[: command_args["limit"]] if "limit" in command_args else mock_response assert command_results.raw_response == mock_response assert command_results.outputs == mock_response assert command_results.outputs_prefix == "HarmonyEP.Rule" assert command_results.outputs_key_field == "id" @pytest.mark.parametrize( "args,command_name,integration_context,response_file,expected_integration_context,expected_poll_result", [ # Mock success first run ( {"job_id": "3"}, "harmony-ep-push-operation-status-list", {}, "push_operation_status_list.json", {"job_id": None, "remediation_operation_id": None}, CommonServerPython.PollResult( response=CommonServerPython.CommandResults( outputs=load_mock_response("push_operation_status_list.json"), outputs_prefix="HarmonyEP.PushOperation", outputs_key_field="job_id", raw_response=load_mock_response("push_operation_status_list.json"), ), continue_to_poll=False, args_for_next_run=None, ), ), # Mock continue to poll ( {"job_id": "3"}, "harmony-ep-push-operation-status-list", {}, "push_operation_status_in_progress.json", None, CommonServerPython.PollResult( response=CommonServerPython.CommandResults( outputs=load_mock_response("push_operation_status_in_progress.json"), outputs_prefix="HarmonyEP.Job", outputs_key_field="id", raw_response=load_mock_response("push_operation_status_in_progress.json"), ), continue_to_poll=True, args_for_next_run={"job_id": "3"}, ), ), # Mock success second run ( {"job_id": "3"}, "harmony-ep-push-operation-status-list", {"job_id": "3"}, "push_operation_status_list.json", {"job_id": None, "remediation_operation_id": None}, CommonServerPython.PollResult( response=CommonServerPython.CommandResults( outputs=load_mock_response("push_operation_status_list.json"), outputs_prefix="HarmonyEP.PushOperation", outputs_key_field="job_id", raw_response=load_mock_response("push_operation_status_list.json"), ), continue_to_poll=False, args_for_next_run=None, ), ), # Mock success first run with push operation data ( {"job_id": "3"}, "harmony-ep-anti-malware-scan", {"job_id": "3", "remediation_operation_id": None}, "push_operation_remediation_data.json", {"job_id": "new1", "remediation_operation_id": "222"}, CommonServerPython.PollResult( response=CommonServerPython.CommandResults( outputs=load_mock_response("push_operation_remediation_data.json"), outputs_prefix="HarmonyEP.Job", outputs_key_field="id", raw_response=load_mock_response("push_operation_remediation_data.json"), ), continue_to_poll=True, args_for_next_run={"job_id": "3"}, ), ), # Mock success second run with push operation data ( {"job_id": "3"}, "harmony-ep-anti-malware-scan", {"job_id": "3", "remediation_operation_id": "222"}, "job_status.json", {"job_id": None, "remediation_operation_id": None}, CommonServerPython.PollResult( response=CommonServerPython.CommandResults( outputs=load_mock_response("job_status.json"), outputs_prefix="HarmonyEP.AntiMalwareScan.PushOperation", outputs_key_field="job_id", raw_response=load_mock_response("job_status.json"), ), continue_to_poll=False, args_for_next_run=None, ), ), ], ) def test_schedule_command( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, args: dict[str, Any], command_name: str, integration_context: dict[str, Any], response_file: str, expected_integration_context: dict[str, Any], expected_poll_result: CommonServerPython.PollResult, ): """Test the schedule_command function. Args: requests_mock (pytest_mock.plugin.MockerFixture): Mocked requests. mock_client (HarmonyEndpoint.Client): Mocked client. args (dict[str, Any]): The arguments to pass to the function. integration_context (dict[str, Any]): The integration context to patch. response_file (str): The file names for the mocked responses. expected_integration_context (dict[str, Any]): The expected integration context. expected_poll_result (CommonServerPython.PollResult): The expected poll result. """ requests_mock.get( f"{API_URL}/jobs/3", json=load_mock_response(response_file), ) if command_name == "harmony-ep-anti-malware-scan": requests_mock.post( f"{API_URL}/remediation/222/results/slim", json={"jobId": "new1"}, ) with ( unittest.mock.patch( "CheckPointHarmonyEndpoint.get_integration_context", return_value=integration_context, ), unittest.mock.patch("CheckPointHarmonyEndpoint.set_integration_context") as mock_set_integration_context, ): poll_result: CommonServerPython.PollResult = CheckPointHarmonyEndpoint.schedule_command( client=mock_client, args=args, command_name=command_name, ) if expected_integration_context: mock_set_integration_context.assert_called_once_with(expected_integration_context) assert poll_result.continue_to_poll == expected_poll_result.continue_to_poll assert poll_result.args_for_next_run == expected_poll_result.args_for_next_run assert poll_result.response.outputs_prefix == expected_poll_result.response.outputs_prefix assert poll_result.response.outputs_key_field == expected_poll_result.response.outputs_key_field @pytest.mark.parametrize( "command_name,request_method,request_function,command_args,endpoint", [ ( "harmony-ep-policy-rule-install", "POST", CheckPointHarmonyEndpoint.rule_policy_install_command, {"job_id": None}, "policy/install", ), ( "harmony-ep-policy-rule-modifications-get", "GET", CheckPointHarmonyEndpoint.rule_modifications_get_command, {"rule_id": "1994", "job_id": None}, "policy/1994/modifications", ), ( "harmony-ep-push-operation-status-list", "GET", CheckPointHarmonyEndpoint.push_operation_status_list_command, {"remediation_operation_id": "11081994", "job_id": None}, "remediation/11081994/status", ), ( "harmony-ep-push-operation-status-list", "GET", CheckPointHarmonyEndpoint.push_operation_status_list_command, {"all_results": True, "remediation_operation_id": None, "job_id": None}, "remediation/status", ), ( "harmony-ep-push-operation-get", "POST", CheckPointHarmonyEndpoint.push_operation_get_command, { "remediation_operation_id": "11081994", "filter_text": None, "job_id": None, }, "remediation/11081994/results/slim", ), ( "harmony-ep-push-operation-abort", "POST", CheckPointHarmonyEndpoint.push_operation_abort_command, {"remediation_operation_id": "11081994", "job_id": None}, "remediation/11081994/abort", ), ( "harmony-ep-anti-malware-scan", "POST", CheckPointHarmonyEndpoint.anti_malware_scan_command, { "comment": "test", "computer_ids": ["3"], "groups_ids_to_exclude": ["a"], "computers_ids_to_include": ["1"], "computers_ids_to_exclude": ["2"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/anti-malware/scan", ), ( "harmony-ep-anti-malware-update", "POST", CheckPointHarmonyEndpoint.anti_malware_update_command, { "comment": "test", "computer_ids": ["3"], "groups_ids_to_exclude": ["a"], "computers_ids_to_include": ["1"], "computers_ids_to_exclude": ["2"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/anti-malware/update", ), ( "harmony-ep-anti-malware-restore", "POST", CheckPointHarmonyEndpoint.anti_malware_restore_command, { "comment": "test", "computer_ids": ["3"], "groups_ids_to_exclude": ["a"], "computers_ids_to_include": ["1"], "computers_ids_to_exclude": ["2"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/anti-malware/restore", ), ( "harmony-ep-forensics-indicator-analyze", "POST", CheckPointHarmonyEndpoint.indicator_analyze_command, { "indicator_type": "IP", "indicator_value": "1.1.1.1", "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/forensics/analyze-by-indicator/ip", ), ( "harmony-ep-forensics-file-quarantine", "POST", CheckPointHarmonyEndpoint.file_quarantine_command, { "file_type": "PATH", "file_value": "file_name", "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/forensics/file/quarantine", ), ( "harmony-ep-forensics-file-restore", "POST", CheckPointHarmonyEndpoint.file_restore_command, { "file_type": "PATH", "file_value": "file_name", "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/forensics/file/restore", ), ( "harmony-ep-remediation-computer-isolate", "POST", CheckPointHarmonyEndpoint.remediation_computer_isolate_command, { "file_type": "PATH", "file_value": "file_name", "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/isolate", ), ( "harmony-ep-remediation-computer-deisolate", "POST", CheckPointHarmonyEndpoint.remediation_computer_deisolate_command, { "file_type": "PATH", "file_value": "file_name", "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/de-isolate", ), ( "harmony-ep-agent-computer-restart", "POST", CheckPointHarmonyEndpoint.computer_restart_command, { "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "force_apps_shutdown": False, "job_id": None, }, "remediation/agent/reset-computer", ), ( "harmony-ep-agent-computer-repair", "POST", CheckPointHarmonyEndpoint.computer_repair_command, { "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/repair-computer", ), ( "harmony-ep-agent-computer-shutdown", "POST", CheckPointHarmonyEndpoint.computer_shutdown_command, { "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "force_apps_shutdown": False, "job_id": None, }, "remediation/agent/shutdown-computer", ), ( "harmony-ep-computer-list", "POST", CheckPointHarmonyEndpoint.computer_list_command, { "computer_ids": ["3"], "job_id": None, }, "asset-management/computers/filtered", ), ( "harmony-ep-agent-process-information-get", "POST", CheckPointHarmonyEndpoint.process_information_get_command, { "computer_ids": ["3"], "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/process/information", ), ( "harmony-ep-agent-process-terminate", "POST", CheckPointHarmonyEndpoint.process_terminate_command, { "computer_ids": ["3"], "name": "test", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/process/terminate", ), ( "harmony-ep-agent-registry-key-add", "POST", CheckPointHarmonyEndpoint.agent_registry_key_add_command, { "computer_ids": ["3"], "hive": "hive", "key": "key", "value_name": "value_name", "value_type": "STRING (REG_GZ)", "value_data": "value_data", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/registry/key/add", ), ( "harmony-ep-agent-registry-key-delete", "POST", CheckPointHarmonyEndpoint.agent_registry_key_delete_command, { "computer_ids": ["3"], "hive": "hive", "key": "key", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/registry/key/delete", ), ( "harmony-ep-agent-file-copy", "POST", CheckPointHarmonyEndpoint.agent_file_copy_command, { "computer_ids": ["3"], "destination_absolute_path": "destination_absolute_path", "source_absolute_path": "source_absolute_path", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/file/copy", ), ( "harmony-ep-agent-file-move", "POST", CheckPointHarmonyEndpoint.agent_file_move_command, { "computer_ids": ["3"], "destination_absolute_path": "destination_absolute_path", "source_absolute_path": "source_absolute_path", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/file/move", ), ( "harmony-ep-agent-file-delete", "POST", CheckPointHarmonyEndpoint.agent_file_delete_command, { "computer_ids": ["3"], "target_absolute_path": "target_absolute_path", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/file/delete", ), ( "harmony-ep-agent-vpn-site-add", "POST", CheckPointHarmonyEndpoint.agent_vpn_site_add_command, { "computer_ids": ["3"], "remote_access_gateway_name": "remote_access_gateway_name", "fingerprint": "fingerprint", "host": "host", "authentication_method": "authentication_method", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/vpn/site/add", ), ( "harmony-ep-agent-vpn-site-remove", "POST", CheckPointHarmonyEndpoint.agent_vpn_site_remove_command, { "computer_ids": ["3"], "display_name": "display_name", "inform_user": True, "allow_postpone": True, "job_id": None, }, "remediation/agent/vpn/site/remove", ), ], ) def test_all_schedule_commands( requests_mock, mock_client: CheckPointHarmonyEndpoint.Client, command_name: str, request_method: str, request_function: Callable, command_args: dict[str, Any], endpoint: str, ): """ Scenario: - Test the process_terminate_command function. Given: - Arguments for the command. When: - Executing the process_terminate_command function. Then: - Ensure that the schedule_command is called with the appropriate arguments. """ requests_mock.request( request_method, f"{API_URL}/{endpoint}", json={"jobId": "tg1108"}, ) with ( unittest.mock.patch("CheckPointHarmonyEndpoint.schedule_command") as mock_schedule_command, unittest.mock.patch("demistomock.command", return_value=command_name), ): request_function(command_args, mock_client) mock_schedule_command.assert_called_once_with(command_args, mock_client, command_name) # test helper commands @pytest.mark.parametrize("page_size, page, limit", [(-1, 0, 10), (5, -1, 5), (5, 5, -1)]) def test_validate_pagination_arguments(page_size, page, limit): """ Given: - invalid values of page_size, page and limit When: - executing validate_pagination_arguments function Then: - Ensure that ValueError is raised """ with pytest.raises(ValueError): CheckPointHarmonyEndpoint.validate_pagination_arguments(page=page, page_size=page_size, limit=limit) @pytest.mark.parametrize( "args,expected", [ ({"limit": "10"}, (0, 10, "Showing page 1.\nCurrent page size: 10.")), ( {"page": "2", "page_size": "5"}, (1, 5, "Showing page 2.\nCurrent page size: 5."), ), ( {"page": "3", "page_size": "5", "limit": "15"}, (2, 5, "Showing page 3.\nCurrent page size: 5."), ), ], ) def test_get_pagination_args(args: dict[str, str], expected): """Test get_pagination_args function. Args: args (dict[str, str]): Pagination arguments. expected (tuple): Updated pagination arguments and pagination message. """ with ( unittest.mock.patch( "CommonServerPython.arg_to_number", side_effect=lambda x: int(x) if x is not None else None, ), unittest.mock.patch("CheckPointHarmonyEndpoint.validate_pagination_arguments") as mock_validate, ): assert CheckPointHarmonyEndpoint.get_pagination_args(args) == expected mock_validate.assert_called() def test_validate_filter_arguments(): """Test validate_filter_arguments function and ensure that ValueError is raised.""" with pytest.raises(ValueError) as exc_info: CheckPointHarmonyEndpoint.validate_filter_arguments(column_name="invalid_name", filter_type="equals") assert "'column_name' must be one of the followings" in str(exc_info.value)