Create a custom group
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Display name for the group
Which asset type this group accepts (immutable after creation)
user, endpoint, any Optional description for the group
Group color
gray, red, orange, amber, green, teal, blue, indigo, purple, pink Whether chat ops is enabled for this group
Whether containment is enabled for this group
When false, outbound updates to the source security product are skipped for detections linked to assets in this group
When true, detections involving assets in this group are always escalated for notification, even when the verdict rule would resolve or only run chat ops
Response
user, endpoint, any When false, outbound updates to the source security product are skipped for detections linked to assets in this group
When true, detections involving assets in this group are always escalated for notification, even when the verdict rule would resolve or only run chat ops
gray, red, orange, amber, green, teal, blue, indigo, purple, pink 
