openapi: 3.1.0 info: title: McAfee ePO Alarms Systems API description: McAfee ePolicy Orchestrator (ePO) REST API for centralized security management, including system management, policy assignment, task scheduling, query execution, and threat event retrieval across managed endpoints. version: '5.10' contact: name: McAfee Support url: https://www.mcafee.com/enterprise/en-us/support.html termsOfService: https://www.mcafee.com/enterprise/en-us/about/legal/terms-of-use.html servers: - url: https://{epo-server}:8443/remote description: McAfee ePO Server variables: epo-server: default: your-epo-server description: Hostname or IP of the ePO server security: - basicAuth: [] tags: - name: Systems description: Manage endpoints and systems registered in ePO paths: /system.find: get: operationId: systemFind summary: McAfee Search for systems description: Search for managed systems in the ePO System Tree matching specified criteria such as name, IP address, tags, or custom properties. tags: - Systems parameters: - name: searchText in: query required: true description: Search string to match against system names, IP addresses, or other properties schema: type: string - $ref: '#/components/parameters/outputType' responses: '200': description: List of matching systems content: application/json: schema: type: array items: $ref: '#/components/schemas/System' '401': description: Authentication failed /system.findTag: get: operationId: systemFindTag summary: McAfee Find systems by tag description: Retrieve a list of systems that have a specific tag applied. tags: - Systems parameters: - name: tagName in: query required: true description: Name of the tag to search for schema: type: string - $ref: '#/components/parameters/outputType' responses: '200': description: List of systems with the specified tag content: application/json: schema: type: array items: $ref: '#/components/schemas/System' '401': description: Authentication failed /system.applyTag: post: operationId: systemApplyTag summary: McAfee Apply a tag to systems description: Apply a tag to one or more systems identified by name or ID. tags: - Systems parameters: - name: names in: query required: true description: Comma-separated list of system names or IDs schema: type: string - name: tagName in: query required: true description: Name of the tag to apply schema: type: string - $ref: '#/components/parameters/outputType' responses: '200': description: Tag applied successfully content: application/json: schema: $ref: '#/components/schemas/CommandResult' '401': description: Authentication failed /system.clearTag: post: operationId: systemClearTag summary: McAfee Remove a tag from systems description: Remove a tag from one or more systems identified by name or ID. tags: - Systems parameters: - name: names in: query required: true description: Comma-separated list of system names or IDs schema: type: string - name: tagName in: query required: true description: Name of the tag to remove schema: type: string - $ref: '#/components/parameters/outputType' responses: '200': description: Tag removed successfully content: application/json: schema: $ref: '#/components/schemas/CommandResult' '401': description: Authentication failed components: parameters: outputType: name: :output in: query required: false description: Output format for the response. Defaults to JSON when not specified. schema: type: string enum: - json - xml - terse - verbose default: json schemas: System: type: object properties: EPOComputerProperties.ParentID: type: integer description: Parent group ID in the System Tree EPOComputerProperties.ComputerName: type: string description: NetBIOS computer name EPOComputerProperties.IPAddress: type: string description: IP address of the system EPOComputerProperties.OSType: type: string description: Operating system type EPOComputerProperties.OSVersion: type: string description: Operating system version EPOComputerProperties.DomainName: type: string description: Domain or workgroup name EPOComputerProperties.UserName: type: string description: Logged-in user name EPOComputerProperties.Tags: type: string description: Comma-separated list of applied tags EPOLeafNode.AgentGUID: type: string description: Unique McAfee Agent GUID EPOLeafNode.AgentVersion: type: string description: Installed McAfee Agent version EPOLeafNode.LastUpdate: type: string format: date-time description: Last agent-server communication time EPOLeafNode.ManagedState: type: string description: Management state of the system CommandResult: type: object properties: result: type: string description: Result status message securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication using ePO administrator credentials. Credentials are transmitted as a Base64-encoded username:password pair. externalDocs: description: McAfee ePO Web API Reference Guide url: https://docs.mcafee.com/bundle/epolicy-orchestrator-web-api-reference-guide