update_alert_assignee
Update the assignee of one or more alerts
How to use it
update_alert_assignee is exposed by the MCP Panther MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the update_alert_assignee tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
FULL MCP PANTHER LISTINGOther tools in MCP Panther (35)
Add a comment to a Panther alert
Bulk update multiple alerts with status, assignee, and/or comment changes
Disable a detection by setting enabled to false. Supports rules, scheduledrules, simplerules, and policies
Retrieve the latest AI triage summary previously generated for a specific alert
Get detailed information about a specific alert
Analyze patterns and relationships across multiple alerts by aggregating their event data into time-based statistics
Get a small sampling of events for a given alert
Get data ingestion metrics by log type and source
Get detailed information about a specific data model
Get detailed information about a specific detection including the detection body and tests. Accepts a list with one detection type: ["rules"], ["scheduledrules"], ["simplerules"], or ["policies"]
Get detailed information and complete Python code for a specific global helper
Get detailed information about a specific HTTP log source by ID
Get detailed information for specific log type schemas
Get the current user's permissions
Get detailed information about a specific role including permissions
Get metrics about alerts grouped by rule
Get detailed information about a specific scheduled query by ID
Get metrics about alerts grouped by severity
Get schema information for a specific table
Get detailed information about a specific user
List all comments for a specific alert
List alerts with comprehensive filtering options (date range, severity, status, etc.)
List data models that control UDM mappings in rules
List all available tables for a specific database in Panther's data lake
List all available data lake databases in Panther
List detections from Panther with comprehensive filtering support. Supports multiple detection types and filtering by name, state, severity, tags, log types, resource types, output IDs (destinations), and more. Returns outputIDs for each detection showing configured alert destinations
List global helper functions with comprehensive filtering options (name search, creator, modifier)
List log sources with optional filters (health status, log types, integration type)
List available log type schemas with optional filters
List all roles with filtering options (name search, role IDs, sort direction)
List all scheduled queries with pagination support
List all Panther user accounts with pagination support
Execute SQL queries against Panther's data lake with synchronous results
Start an AI-powered triage analysis for a Panther alert with intelligent insights and recommendations
Update the status of one or more alerts