The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

REST API call to create label for incident type

Prev Next

You can create a label for the needed incident type.

PUT request URL

https://<epo_server_name:port>/rest/dlp/incidents/createLabels?incidentNature={incidentNature}&labelName={labelName}

Where

  • epo_server_name:port is the server IP address and port number.

  • incidentNature={n} n can be 1, 2, or 3 for incidents of different data vectors (incident nature).

  • labelName label text.

Request Parameters

Parameter name

Description

Required

Values

Authorization

User credentials for ePO - On-prem.

Required

labelName

Text to create a new label.

Required

Number

incidentNature={n}

Incidents generated for data-in-use/motion and data-at-rest can have the same incident IDs. Specify n to differentiate the incident nature. Based on the data vectors, {n} can be:

  • 1 = Retrieve incident details generated for data-in-use/motion

  • 2 = Reserved to retrieve data-at-rest - Endpoint Discovery incidents and can be used when support for Endpoint Discovery custom attributes is added into the product

  • 3 = Retrieve incident details generated for data-at-rest - Network

Required

Number

Sample PUT request URL

https://172.27.108.53:8443/rest/dlp/incidents/createLabels?incidentNature=1&labelName=testLabel

Sample cURL command

curl -k -G -v -X PUT "https://172.27.108.53:8443/rest/dlp/incidents/createLabels" --data-urlencode "incidentNature=1" --data-urlencode "labelName=testLabel#" -u '<user>:<password>'

Response parameters

A message is returned.

Element

Description

Data type

Message

Shows whether a label is created successfully.

String

Sample response

Sucess: Label has been added

Status and error codes

List of HTTP status codes returned for the query.

Code

Description

200 OK

Returns a successful message for the created label.

400 Bad Request

Returns a bad request if:

  • labelName is missing.

  • labelName contains invalid characters.

  • incidentNature is missing.

  • incidentNature has a non-numeric value.

  • incidentNature is not either 1 or 3.

404 Not Found

Incorrect ePO - On-prem URL.

409 Conflict

Duplicate label name

500 Internal Server Error

An error on the server side that failed the request. See the ePO - On-prem orion.log file for more details about the error.