CheckPointHarmonyEndpoint

Checkpoint Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today's complex threat landscape.

Endpoint · Check Point Harmony Endpoint

Details

IDCheckPointHarmonyEndpoint
ProviderCheckPoint Software Technologies
CategoryEndpoint
From Version6.10.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Checkpoint Harmony Endpoint provides a complete endpoint security solution built to protect organizations and the remote workforce from today’s complex threat landscape.
This integration was integrated and tested with version 1 of CheckPointHarmonyEndpoint.

Configure Check Point Harmony Endpoint in Cortex

Parameter Required
Base URL True
Client ID True
Secret Key True
Trust any certificate (not secure) False
Use system proxy settings False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

harmony-ep-job-status-get


Retrieves the status and result (if any) of a given asynchronous operation. A job is a way to monitor the progress of an asynchronous operation while avoiding issues that may manifest during long synchronous waits.

Base Command

harmony-ep-job-status-get

Input

Argument Name Description Required
job_id The ID of the operation to query the status of. Job ID will returned from most of the commands in this integration. It can be found in the context path. Required

Context Output

Path Type Description
HarmonyEP.Job.data String The job data.
HarmonyEP.Job.status String The job status.

Command example


#### Context Example

```json
{
    "HarmonyEP": {
        "Job": {
            "data": {
                "data": [
                    {
                        "machine": {
                            "id": "1",
                            "name": "DESKTOP-1"
                        },
                        "operation": {
                            "response": null,
                            "status": "DA_NOT_INSTALLED"
                        }
                    },
                    {
                        "machine": {
                            "id": "2",
                            "name": "DESKTOP-2"
                        },
                        "operation": {
                            "response": null,
                            "status": "DA_NOT_INSTALLED"
                        }
                    }
                ],
                "metadata": {
                    "count": 2,
                    "from": 0,
                    "to": 100
                }
            },
            "status": "DONE",
            "statusCode": 200,
            "statusType": 2
        }
    }
}

Human Readable Output

Results

data status statusCode statusType
data: {‘machine’: {‘id’: ‘1’, ‘name’: ‘DESKTOP-1’}, ‘operation’: {‘response’: None, ‘status’: ‘DA_NOT_INSTALLED’}},
{‘machine’: {‘id’: ‘2’, ‘name’: ‘DESKTOP-2’}, ‘operation’: {‘response’: None, ‘status’: ‘DA_NOT_INSTALLED’}}
metadata: {“from”: 0, “to”: 100, “count”: 2}
DONE 200 2

harmony-ep-ioc-list


Gets a list of all Indicators of Compromise. Use the filter parameters to fetch specific IOCs.

Base Command

harmony-ep-ioc-list

Input

Argument Name Description Required
filter The indicator value or comment to search for. The filter is case-insensitive. For example, filter ‘efg will match IoCs ‘abcdEFG’, ‘efGGG’, and ‘yEfG’. Optional
field The Indicator of Compromise field to search by. Possible values are: iocValue, iocComment. Default is iocValue. Optional
sort_direction The way to sort the results. Possible values are: ASC, DESC. Default is DESC. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional

Context Output

Path Type Description
HarmonyEP.IOC.comment String The IOC comment.
HarmonyEP.IOC.modifiedOn Number The time the IOC was modified.
HarmonyEP.IOC.value String The IOC value.
HarmonyEP.IOC.type String The IOC type.
HarmonyEP.IOC.id String The IOC ID.

Command example


#### Context Example

```json
{
    "HarmonyEP": {
        "IOC": [
            {
                "comment": "test",
                "id": "3",
                "modifiedOn": "2024-04-03T09:15:04.182Z",
                "type": "Domain",
                "value": "test2.com"
            },
            {
                "comment": "comment",
                "id": "4",
                "modifiedOn": "2024-05-20T13:14:28.290Z",
                "type": "Domain",
                "value": "test1.com"
            }
        ]
    }
}

Human Readable Output

IOC List

Showing page 1.
Current page size: 50.

Id Type Value Comment Modifiedon
3 Domain test2.com test 2024-04-03T09:15:04.182Z
4 Domain test1.com comment 2024-05-20T13:14:28.290Z

harmony-ep-ioc-update


Updates the given Indicators of Compromise with the given parameters.

Base Command

harmony-ep-ioc-update

Input

Argument Name Description Required
ioc_id The ID of the IOC to update. Use harmony-ep-ioc-list command to get all IOC IDs. Required
comment The IOC comment to update. Required
value The IOC value to update. Required
type The IOC type to update. Possible values are: Domain, IP, URL, MD5, SHA1. Required

Context Output

Path Type Description
HarmonyEP.IOC.comment String The IOC comment.
HarmonyEP.IOC.modifiedOn Number The time the IOC was modified.
HarmonyEP.IOC.value String The IOC value.
HarmonyEP.IOC.type String The IOC type.
HarmonyEP.IOC.id String The IOC ID.

Command example

!harmony-ep-ioc-update ioc_id=8 comment=test value=8.8.8.8 type=IP

Context Example

{
    "HarmonyEP": {
        "IOC": {
            "comment": "test",
            "id": "8",
            "modifiedOn": "2024-06-24T06:44:49.214Z",
            "type": "IP",
            "value": "8.8.8.8"
        }
    }
}

Human Readable Output

IOC 8 was updated successfully

Id Type Value Comment Modifiedon
8 IP 8.8.8.8 test 2024-06-24T06:44:49.214Z

harmony-ep-ioc-create


Creates new Indicators of Compromise using the given parameters.

Base Command

harmony-ep-ioc-create

Input

Argument Name Description Required
comment The IOC comment. Required
value The IOC value. For example, 8.8.8.8 for IP or example.com for Domain. Required
type The IOC type. Possible values are: Domain, IP, URL, MD5, SHA1. Required

Context Output

There is no context output for this command.

Command example

!harmony-ep-ioc-create comment=test value=1.1.1.2 type=IP

Human Readable Output

IOC was created successfully.

harmony-ep-ioc-delete


Deletes the given Indicators of Compromise by their ID.

Base Command

harmony-ep-ioc-delete

Input

Argument Name Description Required
ids A A comma-separated list of list of IOC IDs to delete. Use harmony-ep-ioc-list command to get all IOC IDs. Optional
delete_all Whether to delete all IOCs. This action permanently deletes all Indicators of Compromise and cannot be undone. Possible values are: true, false. Default is false. Optional

Context Output

There is no context output for this command.

Command example

!harmony-ep-ioc-delete ids=7

Human Readable Output

IOCs 7 was deleted successfully.

harmony-ep-policy-rule-assignments-get


Gets all entities directly assigned to the given rule.

Base Command

harmony-ep-policy-rule-assignments-get

Input

Argument Name Description Required
rule_id The ID of the rule to get the assignments. Use harmony-ep-rule-metadata-list command to get all rule IDs. Required

Context Output

Path Type Description
HarmonyEP.Rule.Assignments.type String The rule assignment type.
HarmonyEP.Rule.Assignments.name String The rule assignment name.
HarmonyEP.Rule.Assignments.id String The rule assignment ID.

Command example

!harmony-ep-policy-rule-assignments-get rule_id=1a2b

Context Example

{
    "HarmonyEP": {
        "Rule": {
            "assignments": [
                {
                    "id": "456",
                    "name": "ChromeOsLaptops",
                    "type": "VIRTUAL_GROUP"
                }
            ],
            "id": "1a2b"
        }
    }
}

Human Readable Output

Rule 1a2b assignments

Id Name Type
456 ChromeOsLaptops VIRTUAL_GROUP

harmony-ep-policy-rule-assignments-add


Assigns the specified entities to the given rule. Specified IDs that are already assigned to the rule are ignored.

Base Command

harmony-ep-policy-rule-assignments-add

Input

Argument Name Description Required
rule_id The ID of the rule to add assignments to. Use harmony-ep-rule-metadata-list command to get all rule IDs. Required
entities_ids The entity IDs to assign. Required

Context Output

There is no context output for this command.

Command example

!harmony-ep-policy-rule-assignments-add rule_id=1a2b entities_ids=000

Human Readable Output

Entities [‘000’] were assigned to rule 1a2b successfully.

harmony-ep-policy-rule-assignments-remove


Removes the specified entities from the given rule’s assignments. Specified IDs that are not assigned to the rule are ignored.

Base Command

harmony-ep-policy-rule-assignments-remove

Input

Argument Name Description Required
rule_id The ID of the rule to remove assignments from. Use harmony-ep-rule-metadata-list command to get all rule IDs. Required
entities_ids The entity IDs to remove. Required

Context Output

There is no context output for this command.

Command example

!harmony-ep-policy-rule-assignments-remove rule_id=1a2b entities_ids=000

Human Readable Output

Entities [‘000’] were removed from rule 1a2b successfully.

harmony-ep-policy-rule-install


Installs all policies.

Base Command

harmony-ep-policy-rule-install

Input

Argument Name Description Required
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.PolicyRuleInstall.job_id String The job ID of the policy installation.

Command example

!harmony-ep-policy-rule-install job_id=976

Context Example

{
    "HarmonyEP": {
        "PolicyRuleInstall": {
            "job_id": "976"
        }
    }
}

Human Readable Output

Policy was installed successfully

Job ID: 976
No entries.

harmony-ep-policy-rule-modifications-get


Gets information on modifications to a given rule. (Modifications are the additions or removal of assignments on a rule since it was last installed).

Base Command

harmony-ep-policy-rule-modifications-get

Input

Argument Name Description Required
rule_id The ID of the rule to get the modifications of. Use harmony-ep-rule-metadata-list command to get all rule IDs. Required
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.Rule.job_id String The job ID of the remediation operation.
HarmonyEP.Rule.order Number Rule order.
HarmonyEP.Rule.isDefaultRule Boolean Whether or not the rule is the default.
HarmonyEP.Rule.family String A family in the rule-base (legacy and unified).
HarmonyEP.Rule.connectionState String Rule connection state.
HarmonyEP.Rule.comment String Rule comment.
HarmonyEP.Rule.assignments.type String Rule assignments type.
HarmonyEP.Rule.assignments.name String Rule assignments name.
HarmonyEP.Rule.assignments.id String Rule assignments ID.
HarmonyEP.Rule.name String Rule name.
HarmonyEP.Rule.id String Rule ID.
HarmonyEP.Rule.orientation String Rule policy orientation.

Command example

!harmony-ep-policy-rule-modifications-get rule_id=1a2b job_id=999

Context Example

{
    "HarmonyEP": {
        "Rule": {
            "connectionState": "CONNECTED",
            "family": "Access",
            "id": "1a2b",
            "job_id": "999",
            "lastModifiedBy": "talg",
            "lastModifiedOn": {
                "iso-8601": "2024-06-24T09:04:43.000Z",
                "posix": 1719219883000
            },
            "modified": {
                "assignments": {
                    "modified": false
                },
                "order": {
                    "modified": false
                },
                "settings": {
                    "modified": true
                }
            },
            "name": "New Rule 1"
        }
    }
}

Human Readable Output

Rule 1a2b modification

Job ID: 999

Id Name Family Connectionstate Lastmodifiedby Job Id
1a2b New Rule 1 Access CONNECTED talg 999

harmony-ep-policy-rule-metadata-list


Gets the metadata of all rules or the given rule’s metadata. (Metadata refers to all information relating to the rule except it’s actual settings).

Base Command

harmony-ep-policy-rule-metadata-list

Input

Argument Name Description Required
rule_id The ID of the rule to get the metadata. Optional
rule_family An optional ‘Rule Family’ filter. Used to filter the results to only the selected rule family (e.g., only ‘Threat Prevention’). Possible values are: General Settings, Threat Prevention, Data Protection, OneCheck, Deployment, Remote Access VPN, Capsule Docs, Access, Agent Settings. Optional
connection_state An optional ‘Connection State’ filter. Used to filter the results to only the selected Connection State (e.g., only rules pertaining to policies for connected clients). Possible values are: CONNECTED, DISCONNECTED, RESTRICTED. Optional
limit The maximum number of IP lists to return. Default is 50. Optional
all_results Whether to return all of the results or not. Possible values are: true, false. Default is false. Optional

Context Output

Path Type Description
HarmonyEP.Rule.order Number Rule order.
HarmonyEP.Rule.isDefaultRule Boolean Whether or not the rule is the default.
HarmonyEP.Rule.family String A family in the rule-base (legacy and unified).
HarmonyEP.Rule.connectionState String Rule connection state.
HarmonyEP.Rule.comment String Rule comment.
HarmonyEP.Rule.assignments.type String Rule assignments type.
HarmonyEP.Rule.assignments.name String Rule assignments name.
HarmonyEP.Rule.assignments.id String Rule assignments ID.
HarmonyEP.Rule.name String Rule name.
HarmonyEP.Rule.id String Rule ID.
HarmonyEP.Rule.orientation String Rule policy orientation.

Command example

!harmony-ep-policy-rule-metadata-list rule_id=1a2b

Context Example

{
    "HarmonyEP": {
        "Rule": {
            "assignments": [
                {
                    "id": "000",
                    "name": "Entire Organization",
                    "type": "ORGANIZATION_ROOT"
                },
                {
                    "id": "456",
                    "name": "ChromeOsLaptops",
                    "type": "VIRTUAL_GROUP"
                }
            ],
            "comment": "",
            "connectionState": "CONNECTED",
            "family": "Threat Prevention",
            "id": "1a2b",
            "isDefaultRule": true,
            "name": "TalTest",
            "order": 2,
            "orientation": "DEVICE"
        }
    }
}

Human Readable Output

Rule 1a2b metadata

Id Name Family Comment Orientation Connectionstate Assignments
1a2b TalTest Threat Prevention   DEVICE CONNECTED {‘id’: ‘000’, ‘name’: ‘Entire Organization’, ‘type’: ‘ORGANIZATION_ROOT’},
{‘id’: ‘456’, ‘name’: ‘ChromeOsLaptops’, ‘type’: ‘VIRTUAL_GROUP’}

harmony-ep-push-operation-status-list


Gets the current statuses of all remediation operations or if a specific ID is specified, retrieve the current status of the given remediation operation.

Base Command

harmony-ep-push-operation-status-list

Input

Argument Name Description Required
remediation_operation_id Remediation operations ID. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.PushOperation.adminName String The name of the administrator who initiated the operation.
HarmonyEP.PushOperation.aborted Boolean Indicated whether the operation was aborted by an administrator.
HarmonyEP.PushOperation.remainingTimeoutSeconds Number The amount of time, in seconds, the operation will remain active. When elapsed, no more entities will be affected.
HarmonyEP.PushOperation.createdOn Date The date and time the operation was created.
HarmonyEP.PushOperation.type String Remediation operation type.
HarmonyEP.PushOperation.comment String A comment that was provided during the operation’s creation.
HarmonyEP.PushOperation.id String The operation’s ID.
HarmonyEP.PushOperation.overallStatus String Remediation operation status.
HarmonyEP.PushOperation.numberOfAffectedEntities Number The total number of entities affected by the operation.

Command example

!harmony-ep-push-operation-status-list remediation_operation_id=4d

Context Example

{
    "HarmonyEP": {
        "PushOperation": {
            "aborted": true,
            "adminName": "talg",
            "createdOn": "2024-06-20T10:58:19.407Z",
            "id": "d45",
            "job_id": "3",
            "numberOfAffectedEntities": 6,
            "operationParameters": {
                "allowPostpone": false,
                "informUser": true,
                "originalTimeoutSeconds": 86400,
                "schedulingType": "IMMEDIATE"
            },
            "overallStatus": "ABORTED",
            "remainingTimeoutSeconds": 0,
            "type": "AM_SCAN"
        }
    }
}

Human Readable Output

Push operations status list

Job ID: 3

Id Type Createdon Overallstatus
d45 AM_SCAN 2024-06-20T10:58:19.407Z ABORTED

harmony-ep-push-operation-get


Gets the results of a given Remediation Operation. Remediation Operations may produce results such a Forensics Report or yield status updates such as an anti-malware scan progress.

Base Command

harmony-ep-push-operation-get

Input

Argument Name Description Required
remediation_operation_id Remediation operation ID. Use the harmony-ep-remediation-status-list command to get all remediation operation IDs. Required
filter_text Optional free text search in any of the potential response fields excluding “id”. Can be used to search for specific results, devices or IPs, for example. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.PushOperation.response.status String Push operation response status.
HarmonyEP.PushOperation.response.output String Push operation response output.
HarmonyEP.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.PushOperation.machine.name String The client device’s name.
HarmonyEP.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-push-operation-get remediation_operation_id=4d

Context Example

{
    "HarmonyEP": {
        "PushOperation": [
            {
                "job_id": "6",
                "machine": {
                    "id": "5s",
                    "name": "DESKTOP-M4OAKII"
                },
                "operation": {
                    "id": null,
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        ]
    }
}

Human Readable Output

Push operations

Job ID: 6

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
5s DESKTOP-M4OAKII DA_NOT_INSTALLED

harmony-ep-push-operation-abort


Aborts the given remediation operation. Aborting an operation prevents it from being sent to further Harmony Endpoint Clients. Clients that have already received the operation are not affected.

Base Command

harmony-ep-push-operation-abort

Input

Argument Name Description Required
remediation_operation_id Remediation operation ID. Use the harmony-ep-remediation-status-list command to get all remediation operation IDs. Required
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.PushOperationAbort.job_id String The job ID of the remediation operation.

Command example

!harmony-ep-push-operation-abort remediation_operation_id=93 job_id=976

Context Example

{
    "HarmonyEP": {
        "PushOperationAbort": {
            "job_id": "976"
        }
    }
}

Human Readable Output

Remediation operation abort was added to the push operation list successfully

Job ID: 976
No entries.

harmony-ep-anti-malware-scan


Performs an anti-malware scan on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-anti-malware-scan

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.AntiMalwareScan.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.AntiMalwareScan.PushOperation.id String The remediation operation ID.
HarmonyEP.AntiMalwareScan.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.AntiMalwareScan.PushOperation.response.status String Push operation response status.
HarmonyEP.AntiMalwareScan.PushOperation.response.output String Push operation response output.
HarmonyEP.AntiMalwareScan.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.AntiMalwareScan.PushOperation.machine.name String The client device’s name.
HarmonyEP.AntiMalwareScan.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-anti-malware-scan computer_ids=1

Context Example

{
    "HarmonyEP": {
        "AntiMalwareScan": {
            "PushOperation": [
                {
                    "job_id": "13",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Anti-Malware scan was added to the push operation list successfully

Job ID: 13

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-anti-malware-update


Updates the anti-malware Signature Database on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-anti-malware-update

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
update_from_ep_server Determines whether to update from the EP server. Possible values are: true, false. Default is false. Optional
update_from_cp_server Determines whether to update from the CP server. Possible values are: true, false. Default is false. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.AntiMalwareUpdate.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.AntiMalwareUpdate.PushOperation.id String The remediation operation ID.
HarmonyEP.AntiMalwareUpdate.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.AntiMalwareUpdate.PushOperation.response.status String Push operation response status.
HarmonyEP.AntiMalwareUpdate.PushOperation.response.output String Push operation response output.
HarmonyEP.AntiMalwareUpdate.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.AntiMalwareUpdate.PushOperation.machine.name String The client device’s name.
HarmonyEP.AntiMalwareUpdate.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-anti-malware-update computer_ids=1

Context Example

{
    "HarmonyEP": {
        "AntiMalwareUpdate": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Anti-Malware Signature Database update was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-anti-malware-restore


Restores a file that was previously quarantined by the Harmony Endpoint Client’s anti-malware capability. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-anti-malware-restore

Input

Argument Name Description Required
files A list of file paths to restore. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.AntiMalwareRestore.PushOperation.id String The remediation operation ID.
HarmonyEP.AntiMalwareRestore.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.AntiMalwareRestore.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.AntiMalwareRestore.PushOperation.response.status String Push operation response status.
HarmonyEP.AntiMalwareRestore.PushOperation.response.output String Push operation response output.
HarmonyEP.AntiMalwareRestore.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.AntiMalwareRestore.PushOperation.machine.name String The client device’s name.
HarmonyEP.AntiMalwareRestore.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-anti-malware-restore files=test computer_ids=1

Context Example

{
    "HarmonyEP": {
        "AntiMalwareRestore": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

File restore was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-forensics-indicator-analyze


Collects forensics data whenever a computer that matches the given query accesses or executes the given IP, URL, filename, MD5 or path. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-forensics-indicator-analyze

Input

Argument Name Description Required
indicator_type The indictor type to analyze. Possible values are: IP, URL, File, MD5, Path. Required
indicator_value A URL, IP, Path, File or MD5 that when accessed or executed will trigger a forensics report. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
generate_activity_logs Determines whether to generate detailed activity logs. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.IndicatorAnalyze.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.IndicatorAnalyze.PushOperation.id String The remediation operation ID.
HarmonyEP.IndicatorAnalyze.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.IndicatorAnalyze.PushOperation.response.status String Push operation response status.
HarmonyEP.IndicatorAnalyze.PushOperation.response.output String Push operation response output.
HarmonyEP.IndicatorAnalyze.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.IndicatorAnalyze.PushOperation.machine.name String The client device’s name.
HarmonyEP.IndicatorAnalyze.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-forensics-indicator-analyze indicator_type=IP indicator_value=8.8.8.8 computer_ids=1

Context Example

{
    "HarmonyEP": {
        "IndicatorAnalyze": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

IOC analyze was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-forensics-file-quarantine


Quarantines files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-forensics-file-quarantine

Input

Argument Name Description Required
file_type The forensics quarantine item type. Possible values are: PATH, INCIDENT_ID, MD5. Required
file_value The forensics quarantine item value. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.FileQuarantine.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.FileQuarantine.PushOperation.id String The remediation operation ID.
HarmonyEP.FileQuarantine.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.FileQuarantine.PushOperation.response.status String Push operation response status.
HarmonyEP.FileQuarantine.PushOperation.response.output String Push operation response output.
HarmonyEP.FileQuarantine.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.FileQuarantine.PushOperation.machine.name String The client device’s name.
HarmonyEP.FileQuarantine.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-forensics-file-quarantine file_type=PATH file_value=test computer_ids=1

Context Example

{
    "HarmonyEP": {
        "FileQuarantine": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

File quarantine was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-forensics-file-restore


Restores previously quarantined files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-forensics-file-restore

Input

Argument Name Description Required
file_type The forensics quarantine item type. Possible values are: PATH, INCIDENT_ID, MD5. Required
file_value The forensics quarantine item value. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.FileRestore.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.FileRestore.PushOperation.id String The remediation operation ID.
HarmonyEP.FileRestore.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.FileRestore.PushOperation.response.status String Push operation response status.
HarmonyEP.FileRestore.PushOperation.response.output String Push operation response output.
HarmonyEP.FileRestore.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.FileRestore.PushOperation.machine.name String The client device’s name.
HarmonyEP.FileRestore.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-forensics-file-restore file_type=PATH file_value=test computer_ids=1

Context Example

{
    "HarmonyEP": {
        "FileRestore": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

File restore was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-remediation-computer-isolate


Isolates the computers matching the given query. Isolation is the act of denying all network access from a given computer. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-remediation-computer-isolate

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ComputerIsolate.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ComputerIsolate.PushOperation.id String The remediation operation ID.
HarmonyEP.ComputerIsolate.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ComputerIsolate.PushOperation.response.status String Push operation response status.
HarmonyEP.ComputerIsolate.PushOperation.response.output String Push operation response output.
HarmonyEP.ComputerIsolate.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ComputerIsolate.PushOperation.machine.name String The client device’s name.
HarmonyEP.ComputerIsolate.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-remediation-computer-isolate computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ComputerIsolate": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Remediation isolate was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-remediation-computer-deisolate


De-Isolates the computers matching the given query. De-isolating a computer restores its access to network resources. Affects only isolated computers. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-remediation-computer-deisolate

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ComputerDeisolate.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ComputerDeisolate.PushOperation.id String The remediation operation ID.
HarmonyEP.ComputerDeisolate.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ComputerDeisolate.PushOperation.response.status String Push operation response status.
HarmonyEP.ComputerDeisolate.PushOperation.response.output String Push operation response output.
HarmonyEP.ComputerDeisolate.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ComputerDeisolate.PushOperation.machine.name String The client device’s name.
HarmonyEP.ComputerDeisolate.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-remediation-computer-deisolate computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ComputerDeisolate": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Remediation de-isolate was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-computer-restart


Restarts computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-computer-restart

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
force_apps_shutdown Determines whether to force applications shutdown. Possible values are: true, false. Default is false. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ComputerRestart.PushOperation.id String The remediation operation ID.
HarmonyEP.ComputerRestart.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ComputerRestart.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ComputerRestart.PushOperation.response.status String Push operation response status.
HarmonyEP.ComputerRestart.PushOperation.response.output String Push operation response output.
HarmonyEP.ComputerRestart.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ComputerRestart.PushOperation.machine.name String The client device’s name.
HarmonyEP.ComputerRestart.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-computer-restart computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ComputerReset": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Computer reset restore was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-computer-shutdown


Shuts-down computers match the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-computer-shutdown

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
force_apps_shutdown Determines whether to force applications shutdown. Possible values are: true, false. Default is false. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ComputerShutdown.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ComputerShutdown.PushOperation.id String The remediation operation ID.
HarmonyEP.ComputerShutdown.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ComputerShutdown.PushOperation.response.status String Push operation response status.
HarmonyEP.ComputerShutdown.PushOperation.response.output String Push operation response output.
HarmonyEP.ComputerShutdown.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ComputerShutdown.PushOperation.machine.name String The client device’s name.
HarmonyEP.ComputerShutdown.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-computer-shutdown computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ComputerShutdown": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Computer shutdown was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-computer-repair


Repairs the Harmony Endpoint Client installation on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-computer-repair

Input

Argument Name Description Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ComputerRepair.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ComputerRepair.PushOperation.id String The remediation operation ID.
HarmonyEP.ComputerRepair.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ComputerRepair.PushOperation.response.status String Push operation response status.
HarmonyEP.ComputerRepair.PushOperation.response.output String Push operation response output.
HarmonyEP.ComputerRepair.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ComputerRepair.PushOperation.machine.name String The client device’s name.
HarmonyEP.ComputerRepair.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-computer-repair computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ComputerRepair": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Computer repair was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-computer-list


Gets a list of computers matching the given filters. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-computer-list

Input

Argument Name Description Required
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.Computer.job_id String The job ID of the remediation operation.
HarmonyEP.Computer.CapabilitiesInstalled String A list of all installed capabilities.
HarmonyEP.Computer.InstalledAndRunning String A list of installed and running capabilities.
HarmonyEP.Computer.ClientVersion String The computer client version.
HarmonyEP.Computer.DeployTime String The computer deploy time.
HarmonyEP.Computer.Groups String The computer groups.
HarmonyEP.Computer.type String The computer type.
HarmonyEP.Computer.userName String The computer user name.
HarmonyEP.Computer.domainName String The computer domain name.
HarmonyEP.Computer.isolationStatus String The computer isolation status.
HarmonyEP.Computer.ClientVersion String The computer client veraion.
HarmonyEP.Computer.LastLoggedInUser String The computer last login user.
HarmonyEP.Computer.osName String The computer operating system name.
HarmonyEP.Computer.osVersion String The computer operating system version.
HarmonyEP.Computer.ip String The computer IP address.
HarmonyEP.Computer.DeploymentStatus String The computer deployment status.
HarmonyEP.Computer.name String The computer name.
HarmonyEP.Computer.id String The computer’s unique ID.

Command example

!harmony-ep-computer-list computer_ids=1 job_id=845

Context Example

{
    "HarmonyEP": {
        "Computer": {
            "Computer": [
                {
                    "client_version": "87.62.2002",
                    "deployment_status": "Completed",
                    "domain_name": ".WORKGROUP",
                    "groups": [
                        {
                            "id": "666",
                            "name": "Desktops"
                        },
                        {
                            "id": "222",
                            "name": "WinDesktops"
                        }
                    ],
                    "id": "888",
                    "ip": "1.1.1.1",
                    "isolation_status": "Not Isolated",
                    "last_logged_in_user": "ntlocal",
                    "name": "DESKTOP-E7V07D5",
                    "os_name": "Microsoft Windows 10 Pro",
                    "os_version": "10.0-19045-SP0.0-SMP",
                    "type": "Desktop",
                    "user_name": "ntlocal"
                }
            ],
            "job_id": "845"
        }
    }
}

Human Readable Output

Computer list

Job ID: 845

Showing page 1.
Current page size: 50.

Id Name Ip Type Groups User Name Client Version
888 DESKTOP-E7V07D5 1.1.1.1 Desktop {‘id’: ‘666’, ‘name’: ‘Desktops’},
{‘id’: ‘222’, ‘name’: ‘WinDesktops’}
ntlocal 87.62.2002

harmony-ep-agent-process-information-get


Collects information about processes on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-process-information-get

Input

Argument Name Description Required
process_name The name of the process to collect information on. If not provided, all running processes will be collected. Optional
additional_fields Additional process properties to collect. If not provided, only the process’s name and ID will be collected. Possible values are: SI, Handles, VM, WS, PM, NPM, Path, CPU, ExitCode, ExitTime, Handle, HandleCount, HasExited, Id, MachineName, MainModule, MainWindowHandle, MainWindowTitle, MaxWorkingSet, MinWorkingSet, Modules, NonpagedSystemMemorySize, NonpagedSystemMemorySize64, PagedMemorySize, PagedMemorySize64, PagedSystemMemorySize, PagedSystemMemorySize64, PeakPagedMemorySize, PeakPagedMemorySize64, PeakVirtualMemorySize, PeakVirtualMemorySize64, PeakWorkingSet, PeakWorkingSet64, PriorityBoostEnabled, PriorityClass, PrivateMemorySize, PrivateMemorySize64, PrivilegedProcessorTime, ProcessName, ProcessorAffinity, Responding, SafeHandle, SessionId, StandardError, StandardInput, StandardOutput, StartInfo, StartTime, SynchronizingObject, Threads, TotalProcessorTime, UserProcessorTime, VirtualMemorySize, VirtualMemorySize64, WorkingSet, WorkingSet64. Optional
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ProcessInformation.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ProcessInformation.PushOperation.id String The remediation operation ID.
HarmonyEP.ProcessInformation.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ProcessInformation.PushOperation.response.status String Push operation response status.
HarmonyEP.ProcessInformation.PushOperation.response.output String Push operation response output.
HarmonyEP.ProcessInformation.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ProcessInformation.PushOperation.machine.name String The client device’s name.
HarmonyEP.ProcessInformation.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-process-information-get computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ProcessInformation": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Process information fetch was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-process-terminate


Terminates the given process on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-process-terminate

Input

Argument Name Description Required
terminate_all_instances Indicates whether to terminate all processes matching the given name. If set to true while a non-zero PID is given, only a single process with the given name AND PID may be matched. If set to false or not provided, will terminate only the first matching process. Possible values are: true, false. Default is false. Optional
name The name of the process to terminate. Required
pid The ID (PID) of the process to terminate. When used in conjunction with the name field, the PID must match the named process. If both name and PID are provided but the process matching the PID does not match the provided name, the operation will be ignored by the agent. If set to 0 or not provided, the agent will seek to terminate the process or processes as indicated by the name field. Optional
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.ProcessTerminate.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.ProcessTerminate.PushOperation.id String The remediation operation ID.
HarmonyEP.ProcessTerminate.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.ProcessTerminate.PushOperation.response.status String Push operation response status.
HarmonyEP.ProcessTerminate.PushOperation.response.output String Push operation response output.
HarmonyEP.ProcessTerminate.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.ProcessTerminate.PushOperation.machine.name String The client device’s name.
HarmonyEP.ProcessTerminate.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-process-terminate name=test computer_ids=1

Context Example

{
    "HarmonyEP": {
        "ProcessTerminate": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

Process terminate was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-registry-key-add


Adds a given registry key and/or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-registry-key-add

Input

Argument Name Description Required
is_redirected Determines if the key should reside under WOW6432Node. Keys intended for 64bit versions of Windows may target 32bit versions by setting this value to ‘true, thus specifying that the registry key/value be added under the WOW6432Node. Possible values are: true, false. Optional
value_data The actual value to be added the the specified registry key. Required
value_type A registry value’s type. Possible values are: DWORD (REG_DWORD), STRING (REG_GZ). Required
value_name The name of the value to be added to the specified registry key. Required
key The full path path of the key to create or add a value to. For example, ‘SOFTWARE\Node.js\Components’. Required
hive Defines known Windows Registry Hives. For more information, see https://docs.microsoft.com/en-us/windows/win32/sysinfo/predefined-keys. Possible values are: HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT, HKEY_USERS, HKEY_CURRENT_CONFIG. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.RegistryKeyAdd.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.RegistryKeyAdd.PushOperation.id String The remediation operation ID.
HarmonyEP.RegistryKeyAdd.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.RegistryKeyAdd.PushOperation.response.status String Push operation response status.
HarmonyEP.RegistryKeyAdd.PushOperation.response.output String Push operation response output.
HarmonyEP.RegistryKeyAdd.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.RegistryKeyAdd.PushOperation.machine.name String The client device’s name.
HarmonyEP.RegistryKeyAdd.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-registry-key-add value_data=test value_type="STRING (REG_GZ)" value_name=test key=test hive=HKEY_USERS computer_ids=1

Context Example

{
    "HarmonyEP": {
        "RegistryKeyAdd": {
            "PushOperation": {
                "job_id": "54",
                "machine": {
                    "id": "1",
                    "name": "DESKTOP-1"
                },
                "operation": {
                    "id": "88",
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        }
    }
}

Human Readable Output

Registry key add was added to the push operation list successfully

Job ID: 54

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-registry-key-delete


Removes the given registry key or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-registry-key-delete

Input

Argument Name Description Required
is_redirected Determines if the key should be removed from under WOW6432Node. Keys intended for 64bit versions of Windows may target 32bit versions by setting this value to ‘true’, thus specifying that the registry key/value be removed under the WOW6432Node. Possible values are: true, false. Optional
value_name The value to remove from the key. If not provided, the entire key will be deleted. Optional
key The full path path of the key to delete or remove a value from. For example, ‘SOFTWARE\Node.js\Components’. Required
hive Defines known Windows Registry Hives. For more information, see https://docs.microsoft.com/en-us/windows/win32/sysinfo/predefined-keys. Possible values are: HKEY_CURRENT_USER, HKEY_LOCAL_MACHINE, HKEY_CLASSES_ROOT, HKEY_USERS, HKEY_CURRENT_CONFIG. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.RegistryKeyDelete.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.RegistryKeyDelete.PushOperation.id String The remediation operation ID.
HarmonyEP.RegistryKeyDelete.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.RegistryKeyDelete.PushOperation.response.status String Push operation response status.
HarmonyEP.RegistryKeyDelete.PushOperation.response.output String Push operation response output.
HarmonyEP.RegistryKeyDelete.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.RegistryKeyDelete.PushOperation.machine.name String The client device’s name.
HarmonyEP.RegistryKeyDelete.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-registry-key-delete value_name='test' key='test' hive=HKEY_USERS computer_ids=1

Context Example

{
    "HarmonyEP": {
        "RegistryKeyDelete": {
            "PushOperation": {
                "job_id": "54",
                "machine": {
                    "id": "1",
                    "name": "DESKTOP-1"
                },
                "operation": {
                    "id": "88",
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        }
    }
}

Human Readable Output

Registry key delete was added to the push operation list successfully

Job ID: 54

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-file-copy


Copies the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-file-copy

Input

Argument Name Description Required
destination_absolute_path The absolute, full destination path. The provided path must include the target file’s name (e.g., c:\backup\backup1.txt). Required
source_absolute_path The absolute, full source path (e.g., c:\backup\backup1.txt). Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.FileCopy.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.FileCopy.PushOperation.id String The remediation operation ID.
HarmonyEP.FileCopy.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.FileCopy.PushOperation.response.status String Push operation response status.
HarmonyEP.FileCopy.PushOperation.response.output String Push operation response output.
HarmonyEP.FileCopy.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.FileCopy.PushOperation.machine.name String The client device’s name.
HarmonyEP.FileCopy.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-file-copy destination_absolute_path='test.txt' source_absolute_path='test.txt' computer_ids=1

Context Example

{
    "HarmonyEP": {
        "FileCopy": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

File copy was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-file-move


Moves the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-file-move

Input

Argument Name Description Required
destination_absolute_path The absolute, full destination path. The provided path must include the target file’s name (e.g., c:\backup\backup1.txt). Required
source_absolute_path The absolute, full source path (e.g., c:\backup\backup1.txt). Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.FileMove.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.FileMove.PushOperation.id String The remediation operation ID.
HarmonyEP.FileMove.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.FileMove.PushOperation.response.status String Push operation response status.
HarmonyEP.FileMove.PushOperation.response.output String Push operation response output.
HarmonyEP.FileMove.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.FileMove.PushOperation.machine.name String The client device’s name.
HarmonyEP.FileMove.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-file-move destination_absolute_path='test.txt' source_absolute_path='test.txt' computer_ids=1

Context Example

{
    "HarmonyEP": {
        "FileMove": [
            {
                "job_id": "16",
                "machine": {
                    "id": "1",
                    "name": "DESKTOP-1"
                },
                "operation": {
                    "id": null,
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        ]
    }
}

Human Readable Output

File move was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-file-delete


Deletes the given file from the given source on computers matching the given query. This operation is risky! Use with caution as it allows you to change Harmony Endpoint protected files or registry entries that are in use by your operating system. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-file-delete

Input

Argument Name Description Required
target_absolute_path The absolute, full path of the file to remove. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.FileDelete.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.FileDelete.PushOperation.id String The remediation operation ID.
HarmonyEP.FileDelete.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.FileDelete.PushOperation.response.status String Push operation response status.
HarmonyEP.FileDelete.PushOperation.response.output String Push operation response output.
HarmonyEP.FileDelete.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.FileDelete.PushOperation.machine.name String The client device’s name.
HarmonyEP.FileDelete.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-file-delete target_absolute_path='test.txt' computer_ids=1

Context Example

{
    "HarmonyEP": {
        "FileDelete": {
            "PushOperation": [
                {
                    "job_id": "16",
                    "machine": {
                        "id": "1",
                        "name": "DESKTOP-1"
                    },
                    "operation": {
                        "id": null,
                        "response": null,
                        "status": "DA_NOT_INSTALLED"
                    }
                }
            ]
        }
    }
}

Human Readable Output

File delete was added to the push operation list successfully

Job ID: 16

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-vpn-site-add


Adds the given VPN site’s configuration to computers matching the given query. Adding a VPN site allows Harmony Endpoint Clients to connect to it. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-vpn-site-add

Input

Argument Name Description Required
remote_access_gateway_name The remote gateway’s name. Required
fingerprint The remote gateway’s certificate fingerprint. Fingerprints are used to verify the authenticity of the gateway. Required
authentication_method Authentication methods used in conjunction with VPN site standard login. Possible values are: CERTIFICATE, P12_CERTIFICATE, USERNAME_PASSWORD, SECURID_KEY_FOB, SECURID_PIN_PAD, SOFTID, CHALLENGE_RESPONSE. Required
display_name The VPN site’s display name. Optional
host The target site’s host name or IP address. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.id String The remediation operation ID.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.response.status String Push operation response status.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.response.output String Push operation response output.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.name String The client device’s name.
HarmonyEP.VPNsiteConfigurationAdd.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-vpn-site-add remote_access_gateway_name='test' fingerprint='test' authentication_method=CERTIFICATE host='test' computer_ids=1

Context Example

{
    "HarmonyEP": {
        "VPNsiteConfigurationAdd": {
            "PushOperation": {
                "job_id": "67",
                "machine": {
                    "id": "1",
                    "name": "DESKTOP-1"
                },
                "operation": {
                    "id": "23",
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        }
    }
}

Human Readable Output

VPN site configuration remove was added to the push operation list successfully

Job ID: 67

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

harmony-ep-agent-vpn-site-remove


Removes the given VPN site’s configuration to computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

Base Command

harmony-ep-agent-vpn-site-remove

Input

Argument Name Description Required
display_name The display name of the VPN site to remove. If a display name was not provided during the site’s creation, the host name/IP should be used instead. Required
comment Operation comment. Optional
scheduling_date_time Start the operation on a given date and time. If not specified, defaults to ‘Now’ (i.e. immediate execution). For example, “2024-04-12 03:59”. Optional
expiration_seconds The amount of time, in seconds, the operation will be valid for. When the specified time has elapsed, the operation will expire and will not be pushed to any more clients. If not specified, defaults to 86400 seconds (24 hours). Minimum value is 1. Optional
computer_ids A comma-separated list of computer IDs to include in the operation. Optional
computer_names A comma-separated list of computer names to include in the operation. Optional
computer_ips A comma-separated list of computer IPs to include in the operation. Optional
computer_types A comma-separated list of computer types to include in the operation. Possible values are: Desktop, Laptop, N/A, Domain Controller, Server. Optional
computer_deployment_statuses A comma-separated list of computer deployment statuses to include in the operation. Possible values are: Retrying, Error, Scheduled, Downloading, Deploying, Completed, Failed, Uninstalling, Not Scheduled, Not Installed, N/A. Optional
computer_last_connection Computer last connection range time (start time, end time) to include in the operation. For example, “2024-01-01 07:58, 2024-04-02 02:00”. Optional
filter A comma-separated list of list of search filters according to the following template: “column_name operator ‘values_list’ “. For example, the query “computerId Contains ‘1,2,3,4’ , computerIP Exact ‘1.1.1.1’ “ will refer to computers contains ‘1’, ‘2’, ‘3’, and ‘4’ in their ID and that their IP is ‘1.1.1.1’. For more optional ‘column_name’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/ComputerColumnNames. For more optional ‘operator’ values, see https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.179#/FilterType . Optional
groups_ids_to_exclude A comma-separated list of group IDs to exclude from the operation. Optional
computers_ids_to_exclude A comma-separated list of computer IDs to exclude from the operation. Optional
computers_ids_to_include A comma-separated list of computer IDs to include in the operation. Optional
inform_user Determines whether to inform the user, via a UserCheck (popup) message, that the operation is taking place. Possible values are: true, false. Default is true. Optional
allow_postpone Determines whether to allow the user to postpone the operation. Possible values are: true, false. Default is true. Optional
page Page number of paginated results. Minimum value: 1. Optional
page_size The number of items per page. Optional
limit The maximum number of records to retrieve. Default is 50. Optional
interval The interval between each poll in seconds. Minimum value is 10. Default is 30. Optional
timeout The timeout for the polling in seconds. Default is 600. Optional
job_id The job ID to fetch data for. Hidden argument. Optional

Context Output

Path Type Description
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.job_id String The job ID of the remediation operation.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.id String The remediation operation ID.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.status String Describes possible states in which a push operation may be in regards to a specific device.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.response.status String Push operation response status.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.response.output String Push operation response output.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.ipAddress String The client device’s IPv4 address.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.name String The client device’s name.
HarmonyEP.VPNsiteConfigurationRemove.PushOperation.machine.id String The client device’s unique ID.

Command example

!harmony-ep-agent-vpn-site-remove display_name='test' computer_ids=1

Context Example

{
    "HarmonyEP": {
        "VPNsiteConfigurationRemove": {
            "PushOperation": {
                "job_id": "67",
                "machine": {
                    "id": "1",
                    "name": "DESKTOP-1"
                },
                "operation": {
                    "id": "23",
                    "response": null,
                    "status": "DA_NOT_INSTALLED"
                }
            }
        }
    }
}

Human Readable Output

VPN site configuration remove was added to the push operation list successfully

Job ID: 67

Showing page 1.
Current page size: 50.

Machine Id Machine Name Operation Status
1 DESKTOP-1 DA_NOT_INSTALLED

Configuration parameters

  • base_url — Base URL (required)
  • credentials — Client ID (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (35)

  • harmony-ep-agent-computer-repair

    Repairs the Harmony Endpoint Client installation on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-computer-restart

    Restarts computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-computer-shutdown

    Shuts-down computers match the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-file-copy

    Copies the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-file-delete

    Deletes the given file from the given source on computers matching the given query. This operation is risky! Use with caution as it allows you to change Harmony Endpoint protected files or registry entries that are in use by your operating system. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-file-move

    Moves the given file from the given source to the given destination on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-process-information-get

    Collects information about processes on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-process-terminate

    Terminates the given process on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-registry-key-add

    Adds a given registry key and/or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-registry-key-delete

    Removes the given registry key or value to the registry of computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-vpn-site-add

    Adds the given VPN site's configuration to computers matching the given query. Adding a VPN site allows Harmony Endpoint Clients to connect to it. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-agent-vpn-site-remove

    Removes the given VPN site's configuration to computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-anti-malware-restore

    Restores a file that was previously quarantined by the Harmony Endpoint Client's anti-malware capability. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-anti-malware-scan

    Performs an anti-malware scan on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-anti-malware-update

    Updates the anti-malware Signature Database on computers matching the given query. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-computer-list

    Gets a list of computers matching the given filters. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-forensics-file-quarantine

    Quarantines files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-forensics-file-restore

    Restores previously quarantined files given by path or MD5 or detections relating to a forensic incident. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-forensics-indicator-analyze

    Collects forensics data whenever a computer that matches the given query accesses or executes the given IP, URL, filename, MD5 or path. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-ioc-create

    Creates new Indicators of Compromise using the given parameters.

  • harmony-ep-ioc-delete

    Deletes the given Indicators of Compromise by their ID.

  • harmony-ep-ioc-list

    Gets a list of all Indicators of Compromise. Use the filter parameters to fetch specific IOCs.

  • harmony-ep-ioc-update

    Updates the given Indicators of Compromise with the given parameters.

  • harmony-ep-job-status-get

    Retrieves the status and result (if any) of a given asynchronous operation. A job is a way to monitor the progress of an asynchronous operation while avoiding issues that may manifest during long synchronous waits.

  • harmony-ep-policy-rule-assignments-add

    Assigns the specified entities to the given rule. Specified IDs that are already assigned to the rule are ignored.

  • harmony-ep-policy-rule-assignments-get

    Gets all entities directly assigned to the given rule.

  • harmony-ep-policy-rule-assignments-remove

    Removes the specified entities from the given rule's assignments. Specified IDs that are not assigned to the rule are ignored.

  • harmony-ep-policy-rule-install

    Installs all policies.

  • harmony-ep-policy-rule-metadata-list

    Gets the metadata of all rules or the given rule's metadata. (Metadata refers to all information relating to the rule except it's actual settings).

  • harmony-ep-policy-rule-modifications-get

    Gets information on modifications to a given rule. (Modifications are the additions or removal of assignments on a rule since it was last installed).

  • harmony-ep-push-operation-abort

    Aborts the given remediation operation. Aborting an operation prevents it from being sent to further Harmony Endpoint Clients. Clients that have already received the operation are not affected.

  • harmony-ep-push-operation-get

    Gets the results of a given Remediation Operation. Remediation Operations may produce results such a Forensics Report or yield status updates such as an anti-malware scan progress.

  • harmony-ep-push-operation-status-list

    Gets the current statuses of all remediation operations or if a specific ID is specified, retrieve the current status of the given remediation operation.

  • harmony-ep-remediation-computer-deisolate

    De-Isolates the computers matching the given query. De-isolating a computer restores its access to network resources. Affects only isolated computers. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

  • harmony-ep-remediation-computer-isolate

    Isolates the computers matching the given query. Isolation is the act of denying all network access from a given computer. Note that you must specify at least one of the following filter arguments: computer_ids, computer_names, computer_ips, computer_group_names, computer_types, computer_deployment_status, computer_last_connection, or filter.

import json
import os
import unittest.mock
from collections.abc import Callable
from typing import Any

import CheckPointHarmonyEndpoint
import CommonServerPython
import pytest

TEST_DATA = "test_data"
BASE_URL = "https://www.example.com/"
API_URL = CommonServerPython.urljoin(BASE_URL, "app/endpoint-web-mgmt/harmony/endpoint/api/v1")


def load_mock_response(file_name: str) -> dict[str, Any] | list[dict[str, Any]]:
    """Load mock file that simulates an API response.

    Args:
        file_name (str): Name of the mock response JSON file to return.
    Returns:
        dict[str, Any]: Mock file content.
    """
    file_path = os.path.join(TEST_DATA, file_name)

    with open(file_path, encoding="utf-8") as mock_file:
        return json.loads(mock_file.read())


@pytest.fixture()
def mock_client() -> CheckPointHarmonyEndpoint.Client:
    """
    Establish a mock connection to the client with a user name and password.

    Returns:
        Client: Mock connection to client.
    """
    return CheckPointHarmonyEndpoint.Client(
        base_url=API_URL,
        client_id="test",
        client_secret="test",
        verify_certificate=False,
        proxy=False,
    )


@pytest.mark.parametrize(
    "command_args, endpoint, response_file",
    [
        (
            {"job_id": "123"},
            "jobs/123",
            "job_status.json",
        ),
    ],
)
def test_job_status_get_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_args: dict[str, Any],
    endpoint: str,
    response_file: str,
):
    """
    Scenario:
    - Test retrieving job status.

    Given:
    - Arguments for retrieving job status.

    When:
    - Executing job_status_get_command function.

    Then:
    - Ensure that the CommandResults outputs is correct.
    - Ensure that the CommandResults raw_response is correct.
    - Ensure that the CommandResults outputs_prefix is correct.
    - Ensure that the CommandResults outputs_key_field is correct.
    """
    mock_response = load_mock_response(response_file)
    requests_mock.get(
        url=f"{API_URL}/{endpoint}",
        json=mock_response,
    )

    command_results = CheckPointHarmonyEndpoint.job_status_get_command(command_args, mock_client)

    assert command_results.raw_response == mock_response
    assert command_results.outputs == mock_response
    assert command_results.outputs_prefix == "HarmonyEP.Job"
    assert command_results.outputs_key_field == "id"


@pytest.mark.parametrize(
    "command_args, endpoint, response_file",
    [
        (
            {
                "filter": "com",
                "sort_field": "iocValue",
                "sort_direction": "ASC",
            },
            "ioc/get",
            "ioc_list.json",
        ),
    ],
)
def test_ioc_list_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_args: dict[str, Any],
    endpoint: str,
    response_file: str,
):
    """
    Scenario:
    - Test listing IOCs.

    Given:
    - Arguments for listing IOCs.

    When:
    - Executing ioc_list_command function.

    Then:
    - Ensure that the CommandResults outputs is correct.
    - Ensure that the CommandResults raw_response is correct.
    - Ensure that the CommandResults outputs_prefix is correct.
    - Ensure that the CommandResults outputs_key_field is correct.
    """
    mock_response = load_mock_response(response_file)
    requests_mock.post(
        url=f"{API_URL}/{endpoint}",
        json=mock_response,
    )

    command_results = CheckPointHarmonyEndpoint.ioc_list_command(command_args, mock_client)
    mock_response["content"][0]["modifiedOn"] = CheckPointHarmonyEndpoint.convert_unix_to_date_string(
        mock_response["content"][0]["modifiedOn"]
    )

    assert command_results.raw_response == mock_response
    assert command_results.outputs == mock_response["content"]
    assert command_results.outputs_prefix == "HarmonyEP.IOC"
    assert command_results.outputs_key_field == "id"


@pytest.mark.parametrize(
    "command_args, response_file",
    [
        (
            {
                "type": "Domain",
                "value": "tal.com",
                "comment": "Tal Domain Test",
                "ioc_id": "1108",
            },
            "ioc_update.json",
        ),
    ],
)
def test_ioc_update_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_args: dict[str, Any],
    response_file: str,
):
    """
    Scenario:
    - Test updating an IOC.

    Given:
    - Arguments for updating an IOC.

    When:
    - Executing ioc_update_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    - Ensure that the CommandResults raw_response is correct.
    - Ensure that the CommandResults outputs_prefix is correct.
    - Ensure that the CommandResults outputs_key_field is correct.
    """
    mock_response = load_mock_response(response_file)
    requests_mock.put(
        url=f"{API_URL}/ioc/edit",
        json=mock_response,
    )

    command_results = CheckPointHarmonyEndpoint.ioc_update_command(command_args, mock_client)

    assert command_results.raw_response == mock_response
    assert command_results.outputs == mock_response
    assert command_results.outputs_prefix == "HarmonyEP.IOC"
    assert command_results.outputs_key_field == "id"


def test_ioc_create_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
):
    """
    Scenario:
    - Test creating an IOC.

    Given:
    - Arguments for creating an IOC.

    When:
    - Executing ioc_create_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    """
    requests_mock.post(
        url=f"{API_URL}/ioc/create",
        json="",
    )

    command_results = CheckPointHarmonyEndpoint.ioc_create_command(
        {"type": "Domain", "value": "example.com", "comment": "Suspicious domain"},
        mock_client,
    )

    assert command_results.readable_output == "IOC was created successfully."


@pytest.mark.parametrize(
    "command_args, endpoint, response_file, readable_output",
    [
        (
            {"ids": [1, 2, 3], "delete_all": False},
            "ioc/delete?ids=%5B1,%202,%203%5D",
            "ioc_delete.json",
            "IOCs [1, 2, 3] was deleted successfully.",
        ),
        (
            {"ids": None, "delete_all": True},
            "ioc/delete/all",
            "ioc_delete.json",
            "All IOCs were deleted successfully.",
        ),
    ],
)
def test_ioc_delete_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_args: dict[str, Any],
    endpoint: str,
    response_file: str,
    readable_output: str,
):
    """
    Scenario:
    - Test deleting an IOC.

    Given:
    - Arguments for deleting an IOC.

    When:
    - Executing ioc_delete_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    """
    mock_response = load_mock_response(response_file)
    requests_mock.delete(
        url=f"{API_URL}/{endpoint}",
        json=mock_response,
    )

    command_results = CheckPointHarmonyEndpoint.ioc_delete_command(command_args, mock_client)

    assert command_results.readable_output == readable_output


def test_rule_assignments_get_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
):
    """
    Scenario:
    - Test getting rule assignments.

    Given:
    - Arguments for getting rule assignments.

    When:
    - Executing rule_assignments_get_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    """
    mock_response = load_mock_response("rule_assignments.json")
    requests_mock.get(
        url=f"{API_URL}/policy/1/assignments",
        json=mock_response,
    )
    output = {"id": 1, "assignments": mock_response}
    command_results = CheckPointHarmonyEndpoint.rule_assignments_get_command({"rule_id": 1}, mock_client)

    assert command_results.outputs_prefix == "HarmonyEP.Rule"
    assert command_results.outputs_key_field == "id"
    assert command_results.raw_response == mock_response
    assert command_results.outputs == output


def test_rule_assignments_add_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
):
    """
    Scenario:
    - Test adding rule assignments.

    Given:
    - Arguments for adding rule assignments.

    When:
    - Executing rule_assignments_add_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    """

    requests_mock.put(
        url=f"{API_URL}/policy/1/assignments/add",
        json="",
    )

    command_results = CheckPointHarmonyEndpoint.rule_assignments_add_command(
        {"rule_id": 1, "entities_ids": ["3", "4"]}, mock_client
    )

    assert command_results.readable_output == "Entities ['3', '4'] were assigned to rule 1 successfully."


def test_rule_assignments_remove_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
):
    """
    Scenario:
    - Test removing rule assignments.

    Given:
    - Arguments for removing rule assignments.

    When:
    - Executing rule_assignments_remove_command function.

    Then:
    - Ensure that the CommandResults readable_output is correct.
    """

    requests_mock.put(
        url=f"{API_URL}/policy/1/assignments/remove",
        json="",
    )

    command_results = CheckPointHarmonyEndpoint.rule_assignments_remove_command(
        {"rule_id": 1, "entities_ids": ["3", "4"]}, mock_client
    )

    assert command_results.readable_output == "Entities ['3', '4'] were removed from rule 1 successfully."


@pytest.mark.parametrize(
    "command_args, endpoint, response_file",
    [
        (
            {"limit": 2, "all_results": False},
            "policy/metadata",
            "rule_metadata_list.json",
        ),
        (
            {"rule_id": 1, "all_results": True},
            "policy/1/metadata",
            "rule_metadata_get.json",
        ),
    ],
)
def test_rule_metadata_list_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_args: dict[str, Any],
    endpoint: str,
    response_file: str,
):
    """
    Scenario:
    - Test the rule_metadata_list_command function.

    Given:
    - Arguments for the command.

    When:
    - Executing the rule_metadata_list_command function.

    Then:
    - Ensure that the CommandResults are as expected.
    """

    mock_response: dict[str, Any] | list[dict[str, Any]] = load_mock_response(response_file)
    requests_mock.get(
        url=f"{API_URL}/{endpoint}",
        json=mock_response,
    )
    command_results = CheckPointHarmonyEndpoint.rule_metadata_list_command(command_args, mock_client)
    mock_response = mock_response[: command_args["limit"]] if "limit" in command_args else mock_response

    assert command_results.raw_response == mock_response
    assert command_results.outputs == mock_response
    assert command_results.outputs_prefix == "HarmonyEP.Rule"
    assert command_results.outputs_key_field == "id"


@pytest.mark.parametrize(
    "args,command_name,integration_context,response_file,expected_integration_context,expected_poll_result",
    [
        # Mock success first run
        (
            {"job_id": "3"},
            "harmony-ep-push-operation-status-list",
            {},
            "push_operation_status_list.json",
            {"job_id": None, "remediation_operation_id": None},
            CommonServerPython.PollResult(
                response=CommonServerPython.CommandResults(
                    outputs=load_mock_response("push_operation_status_list.json"),
                    outputs_prefix="HarmonyEP.PushOperation",
                    outputs_key_field="job_id",
                    raw_response=load_mock_response("push_operation_status_list.json"),
                ),
                continue_to_poll=False,
                args_for_next_run=None,
            ),
        ),
        # Mock continue to poll
        (
            {"job_id": "3"},
            "harmony-ep-push-operation-status-list",
            {},
            "push_operation_status_in_progress.json",
            None,
            CommonServerPython.PollResult(
                response=CommonServerPython.CommandResults(
                    outputs=load_mock_response("push_operation_status_in_progress.json"),
                    outputs_prefix="HarmonyEP.Job",
                    outputs_key_field="id",
                    raw_response=load_mock_response("push_operation_status_in_progress.json"),
                ),
                continue_to_poll=True,
                args_for_next_run={"job_id": "3"},
            ),
        ),
        # Mock success second run
        (
            {"job_id": "3"},
            "harmony-ep-push-operation-status-list",
            {"job_id": "3"},
            "push_operation_status_list.json",
            {"job_id": None, "remediation_operation_id": None},
            CommonServerPython.PollResult(
                response=CommonServerPython.CommandResults(
                    outputs=load_mock_response("push_operation_status_list.json"),
                    outputs_prefix="HarmonyEP.PushOperation",
                    outputs_key_field="job_id",
                    raw_response=load_mock_response("push_operation_status_list.json"),
                ),
                continue_to_poll=False,
                args_for_next_run=None,
            ),
        ),
        # Mock success first run with push operation data
        (
            {"job_id": "3"},
            "harmony-ep-anti-malware-scan",
            {"job_id": "3", "remediation_operation_id": None},
            "push_operation_remediation_data.json",
            {"job_id": "new1", "remediation_operation_id": "222"},
            CommonServerPython.PollResult(
                response=CommonServerPython.CommandResults(
                    outputs=load_mock_response("push_operation_remediation_data.json"),
                    outputs_prefix="HarmonyEP.Job",
                    outputs_key_field="id",
                    raw_response=load_mock_response("push_operation_remediation_data.json"),
                ),
                continue_to_poll=True,
                args_for_next_run={"job_id": "3"},
            ),
        ),
        # Mock success second run with push operation data
        (
            {"job_id": "3"},
            "harmony-ep-anti-malware-scan",
            {"job_id": "3", "remediation_operation_id": "222"},
            "job_status.json",
            {"job_id": None, "remediation_operation_id": None},
            CommonServerPython.PollResult(
                response=CommonServerPython.CommandResults(
                    outputs=load_mock_response("job_status.json"),
                    outputs_prefix="HarmonyEP.AntiMalwareScan.PushOperation",
                    outputs_key_field="job_id",
                    raw_response=load_mock_response("job_status.json"),
                ),
                continue_to_poll=False,
                args_for_next_run=None,
            ),
        ),
    ],
)
def test_schedule_command(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    args: dict[str, Any],
    command_name: str,
    integration_context: dict[str, Any],
    response_file: str,
    expected_integration_context: dict[str, Any],
    expected_poll_result: CommonServerPython.PollResult,
):
    """Test the schedule_command function.

    Args:
        requests_mock (pytest_mock.plugin.MockerFixture): Mocked requests.
        mock_client (HarmonyEndpoint.Client): Mocked client.
        args (dict[str, Any]): The arguments to pass to the function.
        integration_context (dict[str, Any]): The integration context to patch.
        response_file (str): The file names for the mocked responses.
        expected_integration_context (dict[str, Any]): The expected integration context.
        expected_poll_result (CommonServerPython.PollResult): The expected poll result.
    """
    requests_mock.get(
        f"{API_URL}/jobs/3",
        json=load_mock_response(response_file),
    )

    if command_name == "harmony-ep-anti-malware-scan":
        requests_mock.post(
            f"{API_URL}/remediation/222/results/slim",
            json={"jobId": "new1"},
        )

    with (
        unittest.mock.patch(
            "CheckPointHarmonyEndpoint.get_integration_context",
            return_value=integration_context,
        ),
        unittest.mock.patch("CheckPointHarmonyEndpoint.set_integration_context") as mock_set_integration_context,
    ):
        poll_result: CommonServerPython.PollResult = CheckPointHarmonyEndpoint.schedule_command(
            client=mock_client,
            args=args,
            command_name=command_name,
        )

        if expected_integration_context:
            mock_set_integration_context.assert_called_once_with(expected_integration_context)

    assert poll_result.continue_to_poll == expected_poll_result.continue_to_poll
    assert poll_result.args_for_next_run == expected_poll_result.args_for_next_run
    assert poll_result.response.outputs_prefix == expected_poll_result.response.outputs_prefix
    assert poll_result.response.outputs_key_field == expected_poll_result.response.outputs_key_field


@pytest.mark.parametrize(
    "command_name,request_method,request_function,command_args,endpoint",
    [
        (
            "harmony-ep-policy-rule-install",
            "POST",
            CheckPointHarmonyEndpoint.rule_policy_install_command,
            {"job_id": None},
            "policy/install",
        ),
        (
            "harmony-ep-policy-rule-modifications-get",
            "GET",
            CheckPointHarmonyEndpoint.rule_modifications_get_command,
            {"rule_id": "1994", "job_id": None},
            "policy/1994/modifications",
        ),
        (
            "harmony-ep-push-operation-status-list",
            "GET",
            CheckPointHarmonyEndpoint.push_operation_status_list_command,
            {"remediation_operation_id": "11081994", "job_id": None},
            "remediation/11081994/status",
        ),
        (
            "harmony-ep-push-operation-status-list",
            "GET",
            CheckPointHarmonyEndpoint.push_operation_status_list_command,
            {"all_results": True, "remediation_operation_id": None, "job_id": None},
            "remediation/status",
        ),
        (
            "harmony-ep-push-operation-get",
            "POST",
            CheckPointHarmonyEndpoint.push_operation_get_command,
            {
                "remediation_operation_id": "11081994",
                "filter_text": None,
                "job_id": None,
            },
            "remediation/11081994/results/slim",
        ),
        (
            "harmony-ep-push-operation-abort",
            "POST",
            CheckPointHarmonyEndpoint.push_operation_abort_command,
            {"remediation_operation_id": "11081994", "job_id": None},
            "remediation/11081994/abort",
        ),
        (
            "harmony-ep-anti-malware-scan",
            "POST",
            CheckPointHarmonyEndpoint.anti_malware_scan_command,
            {
                "comment": "test",
                "computer_ids": ["3"],
                "groups_ids_to_exclude": ["a"],
                "computers_ids_to_include": ["1"],
                "computers_ids_to_exclude": ["2"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/anti-malware/scan",
        ),
        (
            "harmony-ep-anti-malware-update",
            "POST",
            CheckPointHarmonyEndpoint.anti_malware_update_command,
            {
                "comment": "test",
                "computer_ids": ["3"],
                "groups_ids_to_exclude": ["a"],
                "computers_ids_to_include": ["1"],
                "computers_ids_to_exclude": ["2"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/anti-malware/update",
        ),
        (
            "harmony-ep-anti-malware-restore",
            "POST",
            CheckPointHarmonyEndpoint.anti_malware_restore_command,
            {
                "comment": "test",
                "computer_ids": ["3"],
                "groups_ids_to_exclude": ["a"],
                "computers_ids_to_include": ["1"],
                "computers_ids_to_exclude": ["2"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/anti-malware/restore",
        ),
        (
            "harmony-ep-forensics-indicator-analyze",
            "POST",
            CheckPointHarmonyEndpoint.indicator_analyze_command,
            {
                "indicator_type": "IP",
                "indicator_value": "1.1.1.1",
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/forensics/analyze-by-indicator/ip",
        ),
        (
            "harmony-ep-forensics-file-quarantine",
            "POST",
            CheckPointHarmonyEndpoint.file_quarantine_command,
            {
                "file_type": "PATH",
                "file_value": "file_name",
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/forensics/file/quarantine",
        ),
        (
            "harmony-ep-forensics-file-restore",
            "POST",
            CheckPointHarmonyEndpoint.file_restore_command,
            {
                "file_type": "PATH",
                "file_value": "file_name",
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/forensics/file/restore",
        ),
        (
            "harmony-ep-remediation-computer-isolate",
            "POST",
            CheckPointHarmonyEndpoint.remediation_computer_isolate_command,
            {
                "file_type": "PATH",
                "file_value": "file_name",
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/isolate",
        ),
        (
            "harmony-ep-remediation-computer-deisolate",
            "POST",
            CheckPointHarmonyEndpoint.remediation_computer_deisolate_command,
            {
                "file_type": "PATH",
                "file_value": "file_name",
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/de-isolate",
        ),
        (
            "harmony-ep-agent-computer-restart",
            "POST",
            CheckPointHarmonyEndpoint.computer_restart_command,
            {
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "force_apps_shutdown": False,
                "job_id": None,
            },
            "remediation/agent/reset-computer",
        ),
        (
            "harmony-ep-agent-computer-repair",
            "POST",
            CheckPointHarmonyEndpoint.computer_repair_command,
            {
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/repair-computer",
        ),
        (
            "harmony-ep-agent-computer-shutdown",
            "POST",
            CheckPointHarmonyEndpoint.computer_shutdown_command,
            {
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "force_apps_shutdown": False,
                "job_id": None,
            },
            "remediation/agent/shutdown-computer",
        ),
        (
            "harmony-ep-computer-list",
            "POST",
            CheckPointHarmonyEndpoint.computer_list_command,
            {
                "computer_ids": ["3"],
                "job_id": None,
            },
            "asset-management/computers/filtered",
        ),
        (
            "harmony-ep-agent-process-information-get",
            "POST",
            CheckPointHarmonyEndpoint.process_information_get_command,
            {
                "computer_ids": ["3"],
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/process/information",
        ),
        (
            "harmony-ep-agent-process-terminate",
            "POST",
            CheckPointHarmonyEndpoint.process_terminate_command,
            {
                "computer_ids": ["3"],
                "name": "test",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/process/terminate",
        ),
        (
            "harmony-ep-agent-registry-key-add",
            "POST",
            CheckPointHarmonyEndpoint.agent_registry_key_add_command,
            {
                "computer_ids": ["3"],
                "hive": "hive",
                "key": "key",
                "value_name": "value_name",
                "value_type": "STRING (REG_GZ)",
                "value_data": "value_data",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/registry/key/add",
        ),
        (
            "harmony-ep-agent-registry-key-delete",
            "POST",
            CheckPointHarmonyEndpoint.agent_registry_key_delete_command,
            {
                "computer_ids": ["3"],
                "hive": "hive",
                "key": "key",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/registry/key/delete",
        ),
        (
            "harmony-ep-agent-file-copy",
            "POST",
            CheckPointHarmonyEndpoint.agent_file_copy_command,
            {
                "computer_ids": ["3"],
                "destination_absolute_path": "destination_absolute_path",
                "source_absolute_path": "source_absolute_path",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/file/copy",
        ),
        (
            "harmony-ep-agent-file-move",
            "POST",
            CheckPointHarmonyEndpoint.agent_file_move_command,
            {
                "computer_ids": ["3"],
                "destination_absolute_path": "destination_absolute_path",
                "source_absolute_path": "source_absolute_path",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/file/move",
        ),
        (
            "harmony-ep-agent-file-delete",
            "POST",
            CheckPointHarmonyEndpoint.agent_file_delete_command,
            {
                "computer_ids": ["3"],
                "target_absolute_path": "target_absolute_path",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/file/delete",
        ),
        (
            "harmony-ep-agent-vpn-site-add",
            "POST",
            CheckPointHarmonyEndpoint.agent_vpn_site_add_command,
            {
                "computer_ids": ["3"],
                "remote_access_gateway_name": "remote_access_gateway_name",
                "fingerprint": "fingerprint",
                "host": "host",
                "authentication_method": "authentication_method",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/vpn/site/add",
        ),
        (
            "harmony-ep-agent-vpn-site-remove",
            "POST",
            CheckPointHarmonyEndpoint.agent_vpn_site_remove_command,
            {
                "computer_ids": ["3"],
                "display_name": "display_name",
                "inform_user": True,
                "allow_postpone": True,
                "job_id": None,
            },
            "remediation/agent/vpn/site/remove",
        ),
    ],
)
def test_all_schedule_commands(
    requests_mock,
    mock_client: CheckPointHarmonyEndpoint.Client,
    command_name: str,
    request_method: str,
    request_function: Callable,
    command_args: dict[str, Any],
    endpoint: str,
):
    """
    Scenario:
    - Test the process_terminate_command function.

    Given:
    - Arguments for the command.

    When:
    - Executing the process_terminate_command function.

    Then:
    - Ensure that the schedule_command is called with the appropriate arguments.
    """
    requests_mock.request(
        request_method,
        f"{API_URL}/{endpoint}",
        json={"jobId": "tg1108"},
    )

    with (
        unittest.mock.patch("CheckPointHarmonyEndpoint.schedule_command") as mock_schedule_command,
        unittest.mock.patch("demistomock.command", return_value=command_name),
    ):
        request_function(command_args, mock_client)
        mock_schedule_command.assert_called_once_with(command_args, mock_client, command_name)


# test helper commands


@pytest.mark.parametrize("page_size, page, limit", [(-1, 0, 10), (5, -1, 5), (5, 5, -1)])
def test_validate_pagination_arguments(page_size, page, limit):
    """
    Given:
     - invalid values of page_size, page and limit

    When:
     - executing validate_pagination_arguments function

    Then:
     - Ensure that ValueError is raised
    """

    with pytest.raises(ValueError):
        CheckPointHarmonyEndpoint.validate_pagination_arguments(page=page, page_size=page_size, limit=limit)


@pytest.mark.parametrize(
    "args,expected",
    [
        ({"limit": "10"}, (0, 10, "Showing page 1.\nCurrent page size: 10.")),
        (
            {"page": "2", "page_size": "5"},
            (1, 5, "Showing page 2.\nCurrent page size: 5."),
        ),
        (
            {"page": "3", "page_size": "5", "limit": "15"},
            (2, 5, "Showing page 3.\nCurrent page size: 5."),
        ),
    ],
)
def test_get_pagination_args(args: dict[str, str], expected):
    """Test get_pagination_args function.

    Args:
        args (dict[str, str]): Pagination arguments.
        expected (tuple): Updated pagination arguments and pagination message.
    """
    with (
        unittest.mock.patch(
            "CommonServerPython.arg_to_number",
            side_effect=lambda x: int(x) if x is not None else None,
        ),
        unittest.mock.patch("CheckPointHarmonyEndpoint.validate_pagination_arguments") as mock_validate,
    ):
        assert CheckPointHarmonyEndpoint.get_pagination_args(args) == expected
        mock_validate.assert_called()


def test_validate_filter_arguments():
    """Test validate_filter_arguments function and ensure that ValueError is raised."""
    with pytest.raises(ValueError) as exc_info:
        CheckPointHarmonyEndpoint.validate_filter_arguments(column_name="invalid_name", filter_type="equals")
    assert "'column_name' must be one of the followings" in str(exc_info.value)