Actions136
- List Actions
- Retrieve List User Mailbox Rules
- Retrieve List User Photo
- Retrieve List Users
- Retrieve List User Sign In Logs
- Retrieve Public Phishing Check
- Retrieve Edit Ca Policy
- Retrieve Edit Exconnector
- Retrieve Edit Spam Filter
- Retrieve Edit Transport Rule
- Retrieve Exec Edit Calendar Permissions
- Retrieve List Deleted Items
- Retrieve Exec Add Spn
- Retrieve Exec Add Trusted Ip
- Retrieve Exec Alerts List
- Retrieve Exec App Approval
- Retrieve Exec Assign App
- Retrieve Exec Assign Policy
- Retrieve Exec Auto Extend Gdap
- Retrieve Exec Bec Check
- Retrieve Exec Clr Imm Id
- Retrieve Exec Convert To Shared Mailbox
- Retrieve Exec Copy For Sent
- Retrieve Exec Cpv Permissions
- Retrieve Exec Create Tap
- Retrieve Exec Delete Gdap Relationship
- Retrieve Exec Delete Gdap Role Mapping
- Retrieve Exec Device Delete
- Retrieve Exec Disable User
- Retrieve Exec Dns Config
- Retrieve Exec Enable Archive
- Retrieve Exec Extension Mapping
- Retrieve Exec Extension Sync
- Retrieve Exec Extension Test
- Retrieve Exec Geo Ip Lookup
- Retrieve Exec Get Local Admin Password
- Retrieve Exec Get Recovery Key
- Retrieve Exec Graph Request
- Retrieve Exec Groups Delete
- Retrieve Exec Groups Delivery Management
- Retrieve Exec Groups Hide From Gal
- Retrieve Exec Hide From Gal
- Retrieve Exec Incidents List
- Retrieve Exec Mailbox Mobile Devices
- Retrieve Exec Maintenance Scripts
- Retrieve Exec Quarantine Management
- Retrieve Exec Reset Mfa
- Retrieve Exec Reset Pass
- Retrieve Exec Restore Deleted
- Retrieve Exec Revoke Sessions
- Retrieve Exec Run Backup
- Retrieve Exec Send Org Message
- Retrieve Exec Send Push
- Retrieve Exec Set Security Alert
- Retrieve Exec Set Security Incident
- Retrieve Exec Standards Run
- Retrieve Exec Sync Ap Devices
- Retrieve Exec Universal Search
- Retrieve Domain Analyser List
- Retrieve Get CIPP Alerts
- Retrieve Get Version
- Retrieve List All Tenant Device Compliance
- Retrieve List Ap Devices
- Retrieve List Apps
- Retrieve List App Status
- Retrieve List Auto Pilot Config
- Retrieve List Azure AD Connect Status
- Retrieve List Basic Auth
- Retrieve List Bpa
- Retrieve List Bpa Templates
- Retrieve List Calendar Permission
- Retrieve List Ca Templates
- Retrieve List Conditional Access P Olicies
- Retrieve List Contacts
- Retrieve List Defender State
- Retrieve List Defender Tvm
- Retrieve List Device Details
- Retrieve List Device
- Retrieve List Domain Analyser
- Retrieve List Domain Health
- Retrieve List Domains
- Retrieve List Exchange Connectors
- Retrieve List Ex Connector Template
- Retrieve List External Tenant Info
- Retrieve List Function Parameters
- Retrieve List Function Stats
- Retrieve List GDAP Invite
- Retrieve List Graph Request
- Retrieve List Groups
- Retrieve List Group Templates
- Retrieve List Inactive Accounts
- Retrieve List Intune Intents
- Retrieve List Intune Policy
- Retrieve List Intune Templates
- Retrieve List Known Ipdb
- Retrieve List Licenses
- Retrieve List Logs
- Retrieve List Mailbox Cas
- Retrieve List Mailboxes
- Retrieve List Mailbox Mobile Devices
- Retrieve List Mailbox Mobile Devices Copy
- Retrieve List Mailbox Permissions
- Retrieve List Mailbox Restores
- Retrieve List Mailbox Rules
- Retrieve List Mailbox Statistics
- Retrieve List Mail Quarantine
- Retrieve List Message Trace
- Retrieve List Mfa Users
- Retrieve List Named Locations
- Retrieve List Oauth Apps
- Retrieve List Ooo
- Retrieve List Org
- Retrieve List Partner Relationships
- Retrieve List Phish Policies
- Retrieve List Recipients
- Retrieve List Roles
- Retrieve List Shared Mailbox Account Enabled
- Retrieve List Shared Mailbox Statistics
- Retrieve List Sharepoint Quota
- Retrieve List Sharepoint Settings
- Retrieve List Signins
- Retrieve List Sites
- Retrieve List Spam Filter
- Retrieve List Spam Filter Templates
- Retrieve List Standards
- Retrieve List Teams
- Retrieve List Teams Activity
- Retrieve List Teams Voice
- Retrieve List Tenant Details
- Retrieve List Tenants
- Retrieve List Transport Rules
- Retrieve List Transport Rules Templates
- Retrieve List User Conditional Access Policies
- Retrieve List User Counts
- Retrieve List User Devices
- Retrieve List User Groups
- Retrieve List User Mailbox Details
Overview
This node interacts with the AvantGuard CIPP API to retrieve detailed information about a specific security incident from a list resource. It is designed to query and fetch exec set security incident data based on multiple filtering criteria such as assignment, classification, determination, status, and others.
Typical use cases include:
- Automating the retrieval of security incident details for further processing or alerting.
- Integrating security incident data into workflows for compliance reporting or incident management.
- Filtering incidents dynamically by various attributes to focus on relevant cases.
For example, a security operations team could use this node to automatically pull incidents assigned to a particular user with a certain classification and status, enabling targeted follow-up actions.
Properties
| Name | Meaning |
|---|---|
| Assigned | Filter incidents by the assigned person or entity. |
| Classification | Filter incidents by their classification type. |
| Determination | Filter incidents by the determination status or outcome. |
| Guid | Unique identifier (GUID) of the specific security incident to retrieve. |
| Redirected | Filter incidents based on whether they have been redirected. |
| Status | Filter incidents by their current status. |
| Tenantfilter | Filter incidents by tenant or organizational scope. |
All these properties are required string inputs that are sent as query parameters in the API request to filter the results accordingly.
Output
The node outputs JSON data representing the retrieved security incident(s) matching the specified filters. The structure corresponds directly to the API response, typically including fields such as incident details, metadata, status, classification, and related attributes.
If the API supports binary data (e.g., attachments), it would be included in the output's binary field; however, based on the provided code and properties, the primary output is JSON-formatted incident data.
Dependencies
- Requires an API key credential for authenticating with the AvantGuard CIPP API.
- Needs the base URL of the AvantGuard resource API configured in the node credentials.
- Depends on the
@avantguardllc/n8n-openapi-nodepackage for building request properties and handling API communication. - The node uses OpenAPI specifications defined in
openapi.jsonto construct requests.
Troubleshooting
- Missing or invalid API credentials: Ensure the API key and base URL are correctly configured in the node credentials.
- Required properties not set: All listed properties are mandatory; missing any will cause the request to fail.
- Incorrect property values: Providing invalid or mismatched filter values may result in empty responses or errors.
- Network or API errors: Check connectivity and API availability if requests time out or return server errors.
- Unexpected response format: If the API changes, the node might not parse the response correctly; verify API version compatibility.
Links and References
- AvantGuard CIPP API Documentation (example placeholder link)
- n8n Custom Node Development Guide
- OpenAPI Specification