Microsoft Azure Sentinel
Microsoft Azure Sentinel is a scalable, cloud-native SIEM solution that provides intelligent security analytics and threat intelligence.
Microsoft Azure Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. This connector enables seamless integration with Swimlane Turbine, allowing users to automate incident management, threat detection, and response actions. By leveraging Azure Sentinel's capabilities, Swimlane Turbine users can enhance their security operations with real-time insights, streamline workflows, and improve threat response times.
Prerequisites
Before you can use the Microsoft Azure Sentinel connector for Turbine, you'll need access to the Azure Sentinel API. This requires the following:
- OAuth 2.0 Client Credentials authentication using the following parameters:
- URL: The endpoint for accessing Azure Sentinel services.
- Client ID: The application ID registered in Azure Active Directory.
- Client Secret: The secret key associated with the client ID.
- Token URL: The URL used to obtain the OAuth token.
- Scopes: The permissions required for accessing Azure Sentinel resources.
Token URL
Use the following as the token URL,
- To run the Log Analytics Query action, use https://login.microsoftonline.com/{tenant_id}/oauth2/token.
- For all other actions, use https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token.
Host URL
- To run the Log Analytics Query action, use https://api.loganalytics.azure.com/.
- For all other actions, use https://management.azure.com/.
Action setup
To run the Incident management actions, you need a Resource Group Name, Subscription ID and Workspace Name.
Steps to create the Azure app:
- Go to the App Registration page in the Azure portal.
- Click New Registration.
- Enter a name for your new application and choose Accounts in this organizational directory only, then click Register at the bottom.
- Navigate to the API permissions tab on the left navigation menu.
- Select Add a permission.
- Add the following permissions.
- Microsoft Graph / SecurityEvents.ReadWrite.All
- WindowsDefenderATP / Alert.ReadWrite.All
- Navigate to the Certificates & Secrets tab and select New client secret.
- Fill out the description and expiration, then click the Add button at the bottom.
- The Value of the secret you just created is the Client Secret needed for the Swimlane asset.
- Navigate to the Overview tab on the left menu.
- The Client ID and Tenant ID needed in the asset are shown on this page.
- Go back to the main Azure portal windows, and click on your app overview. Copy the following values.
- Resource Group Name
- Subscription ID
- Workspace Name
- Workspace ID
Capabilities
The Microsoft Azure Sentinel connector provides the following capabilities:
- Create or Update Fusion Alert Rule
- Create or Update Incident
- Create or Update MSSIC(MicrosoftSecurityIncidentCreation) Alert Rule
- Create or Update Saved Searches
- Create or Update Scheduled Alert Rule
- Delete Alert Rules
- Delete Incident
- Delete Incident Comments
- Delete Saved Searches
- Get Alert Entities
- Get Alert Rules by Rule ID
- Get Entity Insights
- Get Incident
- Get Incident Comment
- Get Saved Searches ... and so on
Known Issues
If you get a 403 HTTP error, you have to add that Azure app to the Sentinel workspace and assign the Contributor Role to it.
Notes
Configurations
MS Azure Sentinel Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | ο»Ώ | string | Required |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
scope | Permission scopes for this action. | array | Required |
raise_on_http_error_codes | HTTP status codes that should raise an error and route the playbook to the on-failure path. By default, all responses (including 4xx/5xx) are treated as successful and follow the on-success path. Add specific codes here (e.g. [404, 500]) to explicitly treat them as failures. | array | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add Comment to Incident
Add a custom comment to an incident in Microsoft Azure Sentinel using identifiers like subscriptionId, resourceGroupName, workspaceName, and incidentId.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/comments/{{incidentCommentId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.api-version | string | Required | API version for the operation. |
path_parameters.subscriptionId | string | Required | Azure subscription ID. pattern is ^[0-9A-Fa-f]ο»Ώ-([0-9A-Fa-f]ο»Ώ-)ο»Ώ[0-9A-Fa-f]ο»Ώ$. |
path_parameters.resourceGroupName | string | Required | The name of the resource group within the user's subscription. The name is case insensitive. minLength is 1, maxLength is 90, pattern is ^[-\w._()]+$. |
path_parameters.workspaceName | string | Required | The name of the workspace. minLength is 1, maxLength is 90. |
path_parameters.incidentId | string | Required | Parameters for the Add Comment to Incident action |
path_parameters.incidentCommentId | string | Required | Parameters for the Add Comment to Incident action |
properties | object | Optional | Parameter for Add Comment to Incident |
properties.message | string | Required | The comment message. |
Input Example
{"parameters":{"api-version":"2020-01-01"},"json_body":{"properties":{"message":"Some message"}},"path_parameters":{"subscriptionId":"string","resourceGroupName":"string","workspaceName":"string","incidentId":"string","incidentCommentId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
properties | object | Output field: properties |
properties.message | string | Response message |
properties.createdTimeUtc | string | Output field: properties.createdTimeUtc |
properties.author | object | Output field: properties.author |
properties.author.objectId | string | Unique identifier |
properties.author.email | string | Output field: properties.author.email |
properties.author.userPrincipalName | string | Name of the resource |
properties.author.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/provider...","name":"4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014","type":"Microsoft.SecurityInsights/incidents/comments","properties":{"message":"Some message","createdTimeUtc":"2019-01-01T13:15:30Z","author":{}}}}
Create or Update MSSIC Alert Rule
Create or update a Microsoft Security Incident Creation alert rule in Azure Sentinel using subscription, resource group, workspace, and rule specifics.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules/{{ruleId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
path_parameters.ruleId | string | Required | Alert rule ID. |
parameters.api-version | string | Required | The API version to use for this operation. |
etag | string | Optional | Parameter for Create or Update MSSIC Alert Rule |
kind | string | Optional | Parameter for Create or Update MSSIC Alert Rule |
properties | object | Optional | Parameter for Create or Update MSSIC Alert Rule |
properties.productFilter | string | Required | Parameter for Create or Update MSSIC Alert Rule |
properties.displayName | string | Required | The display name for alerts created by this alert rule. |
properties.enabled | boolean | Required | Determines whether this alert rule is enabled or disabled. |
properties.alertRuleTemplateName | string | Optional | The Name of the alert rule template used to create this rule. |
properties.description | string | Optional | The description of the alert rule. |
properties.displayNamesExcludeFilter | array | Optional | The alerts' displayNames on which the cases will not be generated. |
properties.displayNamesFilter | array | Optional | The alerts' displayNames on which the cases will be generated. |
properties.severitiesFilter | array | Optional | The alerts' severities on which the cases will be generated. |
Input Example
{"parameters":{"api-version":"2024-03-01"},"json_body":{"etag":"\"260097e0-0000-0d00-0000-5d6fa88f0000\"","kind":"MicrosoftSecurityIncidentCreation","properties":{"productFilter":"Microsoft Cloud App Security","displayName":"testing displayname","enabled":true,"alertRuleTemplateName":"template1","description":"description of the rule","displayNamesExcludeFilter":"Advanced Multi-Stage Attack Detection","displayNamesFilter":"Advanced Multi-Stage Attack Detection","severitiesFilter":"High"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
etag | string | Output field: etag |
type | string | Type of the resource |
kind | string | Output field: kind |
properties | object | Output field: properties |
properties.productFilter | string | Output field: properties.productFilter |
properties.severitiesFilter | object | Output field: properties.severitiesFilter |
properties.displayNamesFilter | object | Name of the resource |
properties.displayName | string | Name of the resource |
properties.enabled | boolean | Output field: properties.enabled |
properties.description | object | Output field: properties.description |
properties.alertRuleTemplateName | object | Name of the resource |
properties.lastModifiedUtc | string | Output field: properties.lastModifiedUtc |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/provider...","name":"microsoftSecurityIncidentCreationRuleExample","etag":"\"260097e0-0000-0d00-0000-5d6fa88f0000\"","type":"Microsoft.SecurityInsights/alertRules","kind":"MicrosoftSecurityIncidentCreation","properties":{"productFilter":"Microsoft Cloud App Security","severitiesFilter":null,"displayNamesFilter":null,"displayName":"testing displayname",...
Create or Update Fusion Alert Rule
Create or update a fusion alert rule in Microsoft Azure Sentinel using subscription ID, resource group, workspace, and rule ID. Requires properties in JSON body and API version.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules/{{ruleId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
path_parameters.ruleId | string | Required | Alert rule ID. |
parameters.api-version | string | Required | The API version to use for this operation. |
kind | string | Optional | The alert rule kind. |
etag | string | Optional | Etag of the azure resource. |
properties | object | Optional | Parameter for Create or Update Fusion Alert Rule |
properties.enabled | boolean | Required | Determines whether this alert rule is enabled or disabled. |
properties.alertRuleTemplateName | string | Required | The Name of the alert rule template used to create this rule. |
Input Example
{"parameters":{"api-version":"2024-03-01"},"json_body":{"kind":"Fusion","etag":"3d00c3ca-0000-0100-0000-5d42d5010000","properties":{"enabled":true,"alertRuleTemplateName":"f71aba3d-28fb-450b-b192-4e76a83015c8"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
etag | string | Output field: etag |
type | string | Type of the resource |
kind | string | Output field: kind |
properties | object | Output field: properties |
properties.displayName | string | Name of the resource |
properties.description | string | Output field: properties.description |
properties.alertRuleTemplateName | string | Name of the resource |
properties.tactics | array | Output field: properties.tactics |
properties.severity | string | Output field: properties.severity |
properties.enabled | boolean | Output field: properties.enabled |
properties.lastModifiedUtc | string | Output field: properties.lastModifiedUtc |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/provider...","name":"myFirstFusionRule","etag":"\"260090e2-0000-0d00-0000-5d6fb8670000\"","type":"Microsoft.SecurityInsights/alertRules","kind":"Fusion","properties":{"displayName":"Advanced Multi-Stage Attack Detection","description":"In this mode, Sentinel combines low fidelity alerts, which themselves may not be...","alertRuleTemplateName":"f71aba3d...
Create or Update Incident
Create or update an incident in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, and incident properties.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
etag | string | Optional | Parameter for Create or Update Incident |
properties | object | Optional | Parameter for Create or Update Incident |
properties.lastActivityTimeUtc | string | Optional | The time of the last activity in the incident. |
properties.firstActivityTimeUtc | string | Optional | The time of the first activity in the incident. |
properties.description | string | Optional | The description of the incident. |
properties.title | string | Required | The title of the incident. |
properties.owner | object | Optional | Describes a user that the incident is assigned to. |
properties.owner.assignedTo | string | Optional | Parameter for Create or Update Incident |
properties.owner.email | string | Optional | Parameter for Create or Update Incident |
properties.owner.objectId | string | Optional | Unique identifier |
properties.owner.ownerType | string | Optional | Type of the resource |
properties.owner.userPrincipalName | string | Optional | Name of the resource |
properties.severity | string | Required | The severity of the incident. |
properties.classification | string | Optional | The reason the incident was closed. |
properties.classificationComment | string | Optional | Describes the reason the incident was closed. |
properties.classificationReason | string | Optional | The classification reason the incident was closed with. |
properties.status | string | Required | The status of the incident. |
properties.labels | array | Optional | List of labels relevant to this incident. |
properties.labels.labelName | string | Optional | Name of the resource |
properties.labels.labelType | string | Optional | Type of the resource |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"},"etag":"string","properties":{"lastActivityTimeUtc":"string","firstActivityTimeUtc":"string","description":"string","title":"string","owner":{"assignedTo":"string","email":"[email protected]","objectId":"string","ownerType":"string","userPrincipalName":"Example Name"},"severity":"string","classification":"string","classificationComment":"string","classificationReason":"string","status":"active","labels":[{"labelName":"Example Name","labelType":"string"}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.lastModifiedTimeUtc | string | Output field: properties.lastModifiedTimeUtc |
properties.createdTimeUtc | string | Output field: properties.createdTimeUtc |
properties.lastActivityTimeUtc | string | Output field: properties.lastActivityTimeUtc |
properties.firstActivityTimeUtc | string | Output field: properties.firstActivityTimeUtc |
properties.description | string | Output field: properties.description |
properties.title | string | Output field: properties.title |
properties.owner | object | Output field: properties.owner |
properties.owner.objectId | string | Unique identifier |
properties.owner.email | string | Output field: properties.owner.email |
properties.owner.userPrincipalName | string | Name of the resource |
properties.owner.assignedTo | string | Output field: properties.owner.assignedTo |
properties.owner.ownerType | string | Type of the resource |
properties.severity | string | Output field: properties.severity |
properties.classification | string | Output field: properties.classification |
properties.classificationComment | string | Output field: properties.classificationComment |
properties.classificationReason | string | Response reason phrase |
properties.status | string | Status value |
properties.incidentUrl | string | URL endpoint for the request |
Output Example
{"status_code":201,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Content-Length":"1480","Content-Type":"application/json; charset=utf-8","Expires":"-1","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"02b3f250-c3ec-47bc-9bf6-13c2233ea13d","x-ms-correlation-request-id":"02b3f250-c3ec-47bc-9bf6-13c2233ea13d","x-ms-routing-request-id":"SOUTHINDIA:20230729T120425Z:02b3f250-c3ec-47bc-9bf6-13c2233ea13d","Strict-Transport-Securi...
Create Or Update Saved Searches
Create or update saved searches in Microsoft Azure Sentinel using resource group, search ID, subscription, workspace name, and properties.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourcegroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/savedSearches/{{savedSearchId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.savedSearchId | string | Required | The id of the saved search. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
parameters.api-version | string | Required | The API version to use for this operation. |
etag | string | Optional | The ETag of the saved search. To override an existing saved search, use "*" or specify the current Etag. |
properties | object | Optional | Parameter for Create Or Update Saved Searches |
properties.category | string | Required | The category of the saved search. This helps the user to find a saved search faster. |
properties.displayName | string | Required | Saved search display name. |
properties.functionAlias | string | Optional | The function alias if query serves as a function. |
properties.functionParameters | string | Optional | The optional function parameters if query serves as a function. |
properties.query | string | Required | The query expression for the saved search. |
properties.tags | array | Optional | The tags attached to the saved search. |
properties.tags.name | string | Optional | Name of the resource |
properties.tags.value | string | Optional | Value for the parameter |
properties.version | number | Optional | The version number of the query language. The current version is 2 and is the default. |
Input Example
{"parameters":{"api-version":"2020-08-01"},"json_body":{"etag":"","properties":{"category":"Saved Search Test Category","displayName":"Create or Update Saved Search Test","functionAlias":"heartbeat_func","functionParameters":"a:int=1","query":"Heartbeat | summarize Count() by Computer | take a","tags":[{"name":"Group","value":"Computer"}],"version":2}},"path_parameters":{"resourceGroupName":"","savedSearchId":"00000000-0000-0000-0000-00000000000","subscriptionId":"Azure subscription 1","workspaceName":""}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.category | string | Output field: properties.category |
properties.displayName | string | Name of the resource |
properties.query | string | Output field: properties.query |
properties.version | number | Output field: properties.version |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","x-ms-ratelimit-remaining-subscription-writes":"1199","Request-Context":"appId=cid-v1:e6336c63-aab2-45f0-996a-e5dbab2a1508","X-Content-Type-Options":"nosniff","Strict-Transport-Security":"max-age=31536000; includeSubDomains","Access-Control-Allow-Origin":"*","X-Powered...
Create or Update Scheduled Alert Rule
Create or update a ScheduledAlertRule in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, rule ID, and properties.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules/{{ruleId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
path_parameters.ruleId | string | Required | Alert rule ID. |
parameters.api-version | string | Required | The API version to use for this operation. |
kind | string | Optional | The alert rule kind. |
etag | string | Optional | Etag of the azure resource. |
properties | object | Optional | Parameter for Create or Update Scheduled Alert Rule |
properties.alertRuleTemplateName | string | Optional | The Name of the alert rule template used to create this rule. |
properties.displayName | string | Required | The display name for alerts created by this alert rule. |
properties.description | string | Optional | The description of the alert rule. |
properties.severity | string | Required | The severity for alerts created by this alert rule. |
properties.enabled | boolean | Required | Determines whether this alert rule is enabled or disabled. |
properties.tactics | array | Optional | The tactics of the alert rule. |
properties.techniques | array | Optional | The techniques of the alert rule. |
properties.templateVersion | string | Optional | The version of the alert rule template used to create this rule - in format <a.b.c>, where all are numbers, for example 0 <1.0.2>. |
properties.query | string | Required | The query that creates alerts for this rule. |
properties.queryFrequency | string | Required | The frequency (in ISO 8601 duration format) for this alert rule to run. |
properties.queryPeriod | string | Required | The period (in ISO 8601 duration format) that this alert rule looks at. |
properties.triggerOperator | string | Required | The operation against the threshold that triggers alert rule. |
properties.triggerThreshold | number | Required | The threshold triggers this alert rule. |
properties.suppressionDuration | string | Required | The suppression (in ISO 8601 duration format) to wait since last time this alert rule been triggered. |
properties.suppressionEnabled | boolean | Required | Determines whether the suppression for this alert rule is enabled or disabled. |
properties.eventGroupingSettings | object | Optional | The event grouping settings. |
properties.eventGroupingSettings.aggregationKind | string | Optional | The event grouping aggregation kinds. |
Input Example
{"parameters":{"api-version":"2024-03-01"},"json_body":{"kind":"Scheduled","etag":"\"0300bf09-0000-0000-0000-5c37296e0000\"","properties":{"alertRuleTemplateName":"","displayName":"My scheduled rule","description":"An example for a scheduled rule","severity":"High","enabled":true,"tactics":["Persistence","LateralMovement"],"techniques":["xyz"],"templateVersion":"","query":"Heartbeat","queryFrequency":"PT1H","queryPeriod":"P2DT1H30M","triggerOperator":"GreaterThan","triggerThreshold":0,"suppressionDuration":"PT1H","suppressionEnabled":false,"eventGroupingSettings":{"aggregationKind":"AlertPerResult"},"customDetails":{"OperatingSystemName":"OSName","OperatingSystemType":"OSType"},"entityMappings":[{"entityType":"Host","fieldMappings":[{"identifier":"FullName","columnName":"Computer"}]}],"alertDetailsOverride":{"alertDisplayNameFormat":"Alert from {{Computer}}","alertDescriptionFormat":"Suspicious activity was made by {{ComputerIP}}","alertDynamicProperties":[{"alertProperty":"ProductComponentName","value":"ProductComponentNameCustomColumn"}]},"incidentConfiguration":{"createIncident":true,"groupingConfiguration":{"enabled":true,"reopenClosedIncident":false,"lookbackDuration":"PT5H","matchingMethod":"Selected","groupByEntities":["Host"],"groupByAlertDetails":["DisplayName"],"groupByCustomDetails":["OperatingSystemType","OperatingSystemName"]}}}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
kind | string | Output field: kind |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.alertRuleTemplateName | object | Name of the resource |
properties.displayName | string | Name of the resource |
properties.description | string | Output field: properties.description |
properties.severity | string | Output field: properties.severity |
properties.enabled | boolean | Output field: properties.enabled |
properties.tactics | array | Output field: properties.tactics |
properties.query | string | Output field: properties.query |
properties.queryFrequency | string | Output field: properties.queryFrequency |
properties.queryPeriod | string | Output field: properties.queryPeriod |
properties.triggerOperator | string | Output field: properties.triggerOperator |
properties.triggerThreshold | number | Output field: properties.triggerThreshold |
properties.suppressionDuration | string | Output field: properties.suppressionDuration |
properties.suppressionEnabled | boolean | Output field: properties.suppressionEnabled |
properties.lastModifiedUtc | string | Output field: properties.lastModifiedUtc |
properties.eventGroupingSettings | object | Output field: properties.eventGroupingSettings |
properties.eventGroupingSettings.aggregationKind | string | Output field: properties.eventGroupingSettings.aggregationKind |
properties.customDetails | object | Output field: properties.customDetails |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/provider...","name":"73e01a99-5cd7-4139-a149-9f2736ff2ab5","type":"Microsoft.SecurityInsights/alertRules","kind":"Scheduled","etag":"\"0300bf09-0000-0000-0000-5c37296e0000\"","properties":{"alertRuleTemplateName":null,"displayName":"My scheduled rule","description":"An example for a scheduled rule","severity":"High","enabled":true,"tactics":[],"query":...
Delete Alert Rules
Remove specified alert rules in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, and rule ID.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules/{{ruleId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleId | string | Required | Alert rule ID. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
parameters.api-version | string | Required | The API version to use for this operation. |
Input Example
{"parameters":{"api-version":"2024-03-01"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Delete Incident
Remove a specified incident from Microsoft Azure Sentinel using subscription, resource group, workspace, and incident IDs.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-deletes":"14999","x-ms-request-id":"a1c0a95a-ab5c-40ac-819e-fa5d49e3c2db","x-ms-correlation-request-id":"a1c0a95a-ab5c-40ac-819e-fa5d49e3c2db","x-ms-routing-request-id":"SOUTHINDIA:20230729T121753Z:a1c0a95a-ab5c...
Delete Incident Comments
Remove a specific comment from an incident in Microsoft Azure Sentinel using identifiers like incidentCommentId, subscriptionId, resourceGroupName, workspaceName, and incidentId.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/comments/{{incidentCommentId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.incidentCommentId | string | Required | Incident comment ID. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern is ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
path_parameters.incidentId | string | Required | Incident ID. |
parameters.api-version | string | Required | The API version to use for this operation. |
Input Example
{"parameters":{"api-version":"2023-02-01"},"path_parameters":{"incidentCommentId":"4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014","subscriptionId":"d0cfe6b2-9ac0-4464-9919-dccaee2e48c0","resourceGroupName":"myRg","workspaceName":"myWorkspace","incidentId":"73e01a99-5cd7-4139-a149-9f2736ff2ab5"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Delete Saved Searches
Remove a specified saved search from an Azure Sentinel workspace using resource group, search ID, subscription ID, and workspace name.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourcegroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/savedSearches/{{savedSearchId}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.resourceGroupName | string | Required | Parameters for the Delete Saved Searches action |
path_parameters.savedSearchId | string | Required | Parameters for the Delete Saved Searches action |
path_parameters.subscriptionId | string | Required | Parameters for the Delete Saved Searches action |
path_parameters.workspaceName | string | Required | Parameters for the Delete Saved Searches action |
parameters.api-version | string | Required | Parameters for the Delete Saved Searches action |
Input Example
{"parameters":{"api-version":"2020-08-01"},"path_parameters":{"resourceGroupName":"Test","savedSearchId":"00000000-0000-0000-0000-00000000000","subscriptionId":"Azure subscription 1","workspaceName":"Test"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Expires":"-1","x-ms-ratelimit-remaining-subscription-deletes":"14999","Request-Context":"appId=cid-v1:e6336c63-aab2-45f0-996a-e5dbab2a1508","X-Content-Type-Options":"nosniff","Strict-Transport-Security":"max-age=31536000; includeSubDomains","Access-Control-Allow-Origin":"*","X-Powered-By":"ASP.NET","x-ms-request-id":"1744d53b-b782-4116-9086-1ef0d39b76ba","x-ms-correlation-request-id":"1744d53b-b782-4116-9086-1...
Entities Expand
Expand a specific entity in Microsoft Azure Sentinel using entityId, subscriptionId, resourceGroupName, and workspaceName.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/entities/{{entityId}}/expand
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.api-version | string | Required | The API version to use for this operation. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
path_parameters.entityId | string | Required | entity ID. |
expansionId | string | Optional | The end date filter, so the only expansion results returned are before this date. |
startTime | string | Optional | The Id of the expansion to perform. |
endTime | string | Optional | The start date filter, so the only expansion results returned are after this date. |
Input Example
{"parameters":{"api-version":"2024-03-01"},"json_body":{"expansionId":"a77992f3-25e9-4d01-99a4-5ff606cc410a","startTime":"2019-04-25T00:00:00.000Z","endTime":"2019-05-26T00:00:00.000Z"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | object | Value for the parameter |
value.entities | array | Value for the parameter |
value.entities.id | string | Unique identifier |
value.entities.name | string | Name of the resource |
value.entities.type | string | Type of the resource |
value.entities.kind | string | Value for the parameter |
value.entities.properties | object | Value for the parameter |
value.entities.properties.address | string | Value for the parameter |
value.entities.properties.friendlyName | string | Name of the resource |
value.edges | array | Value for the parameter |
value.edges.targetEntityId | string | Unique identifier |
value.edges.additionalData | object | Response data |
value.edges.additionalData.EpochTimestamp | string | Response data |
value.edges.additionalData.FirstSeen | string | Response data |
value.edges.additionalData.Source | string | Response data |
metaData | object | Response data |
metaData.aggregations | array | Response data |
metaData.aggregations.entityKind | string | Response data |
metaData.aggregations.count | number | Response data |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"value":{"entities":[],"edges":[]},"metaData":{"aggregations":[]}}}
Get Alert Rules by Rule ID
Retrieve details for a specific alert rule in Microsoft Azure Sentinel using subscription, resource group, workspace, and rule IDs.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules/{{ruleId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ruleId | string | Required | Alert rule ID. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
parameters.api-version | string | Required | The API version to use for this operation. |
Input Example
{"parameters":{"api-version":"2024-03-01"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
etag | string | Output field: etag |
type | string | Type of the resource |
kind | string | Output field: kind |
properties | object | Output field: properties |
properties.displayName | string | Name of the resource |
properties.description | string | Output field: properties.description |
properties.alertRuleTemplateName | string | Name of the resource |
properties.tactics | array | Output field: properties.tactics |
properties.severity | string | Output field: properties.severity |
properties.enabled | boolean | Output field: properties.enabled |
properties.lastModifiedUtc | string | Output field: properties.lastModifiedUtc |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"id":"/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/provider...","name":"myFirstFusionRule","etag":"\"260090e2-0000-0d00-0000-5d6fb8670000\"","type":"Microsoft.SecurityInsights/alertRules","kind":"Fusion","properties":{"displayName":"Advanced Multi-Stage Attack Detection","description":"In this mode, Sentinel combines low fidelity alerts, which themselves may not be...","alertRuleTemplateName":"f71aba3d...
Get Entity Insights
Retrieve time-specific insights for an entity in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, entity ID, API version, start time, and end time.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/entities/{{entityId}}/getInsights
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.api-version | string | Required | The API version to use for this operation. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. |
path_parameters.workspaceName | string | Required | The name of the workspace. |
path_parameters.entityId | string | Required | entity ID |
addDefaultExtendedTimeRange | boolean | Optional | Indicates if query time range should be extended with default time range of the query. |
startTime | string | Optional | The start timeline date, so the results returned are after this date. |
endTime | string | Optional | The end timeline date, so the results returned are before this date. |
insightQueryIds | array | Optional | List of Insights Query Id. If empty, default value is all insights of this entity. |
Input Example
{"parameters":{"api-version":"2025-04-01-preview"},"json_body":{"addDefaultExtendedTimeRange":false,"startTime":"2021-09-01T00:00:00.000Z","endTime":"2021-10-01T00:00:00.000Z","insightQueryIds":["cae8d0aa-aa45-4d53-8d88-17dd64ffd4e4"]},"path_parameters":{"subscriptionId":"d0cfe6b2-9ac0-4464-9919-dccaee2e48c0","resourceGroupName":"myRg","workspaceName":"myWorkspace","entityId":"e1d3d618-e11f-478b-98e3-bb381539a8e1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
value | array | Value for the parameter |
value.tableQueryResults | object | Value for the parameter |
value.tableQueryResults.columns | array | Value for the parameter |
value.tableQueryResults.columns.name | string | Name of the resource |
value.tableQueryResults.columns.type | string | Type of the resource |
value.tableQueryResults.rows | array | Value for the parameter |
value.tableQueryResults.rows.0 | string | Value for the parameter |
value.tableQueryResults.rows.1 | string | Value for the parameter |
value.tableQueryResults.rows.2 | string | Value for the parameter |
value.tableQueryResults.rows.3 | string | Value for the parameter |
value.tableQueryResults.rows.4 | string | Value for the parameter |
value.chartQueryResults | array | Value for the parameter |
value.chartQueryResults.columns | array | Value for the parameter |
value.chartQueryResults.columns.name | string | Name of the resource |
value.chartQueryResults.columns.type | string | Type of the resource |
value.chartQueryResults.rows | array | Value for the parameter |
value.chartQueryResults.rows.0 | string | Value for the parameter |
value.chartQueryResults.rows.1 | string | Value for the parameter |
value.chartQueryResults.rows.2 | string | Value for the parameter |
value.queryTimeInterval | object | Value for the parameter |
value.queryTimeInterval.startTime | string | Value for the parameter |
value.queryTimeInterval.endTime | string | Value for the parameter |
value.queryId | string | Unique identifier |
metaData | object | Response data |
Output Example
{"status_code":200,"json_body":{"value":[{}],"metaData":{"totalCount":7,"errors":[]}}}
Get Incident
Retrieve detailed information for a specified incident in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, and incident ID.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.lastModifiedTimeUtc | string | Output field: properties.lastModifiedTimeUtc |
properties.createdTimeUtc | string | Output field: properties.createdTimeUtc |
properties.lastActivityTimeUtc | string | Output field: properties.lastActivityTimeUtc |
properties.firstActivityTimeUtc | string | Output field: properties.firstActivityTimeUtc |
properties.description | string | Output field: properties.description |
properties.title | string | Output field: properties.title |
properties.owner | object | Output field: properties.owner |
properties.owner.objectId | string | Unique identifier |
properties.owner.email | string | Output field: properties.owner.email |
properties.owner.userPrincipalName | string | Name of the resource |
properties.owner.assignedTo | string | Output field: properties.owner.assignedTo |
properties.severity | string | Output field: properties.severity |
properties.classification | string | Output field: properties.classification |
properties.classificationComment | string | Output field: properties.classificationComment |
properties.classificationReason | string | Response reason phrase |
properties.status | string | Status value |
properties.incidentUrl | string | URL endpoint for the request |
properties.incidentNumber | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-reads":"11999","x-ms-request-id":"80a0943c-0eaa-4a3d-bac9-1e4e4eae73db","x-ms-correlation-request-id":"80a0943c-0eaa-4a3d-bac9-1e4e4eae73db","x-ms-routing-request-id":"SOUTHINDIA:20230729T122616Z:80a0943c-0eaa-4...
Get Incident Comment
Retrieve a specific comment from an incident in Microsoft Azure Sentinel using subscription, resource group, workspace, and incident IDs.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/comments/{{incidentCommentId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | Parameters for the Get Incident Comment action |
path_parameters.resourceGroupName | string | Required | Parameters for the Get Incident Comment action |
path_parameters.workspaceName | string | Required | Parameters for the Get Incident Comment action |
path_parameters.incidentId | string | Required | Parameters for the Get Incident Comment action |
path_parameters.incidentCommentId | string | Required | Parameters for the Get Incident Comment action |
parameters.api-version | string | Required | Parameters for the Get Incident Comment action |
Input Example
{"parameters":{"api-version":"2023-02-01"},"path_parameters":{"subscriptionId":"38d4cde9-8ef2-4c61-bc61-7fa8658ab74b","resourceGroupName":"test","workspaceName":"swimlaneazuresentinel","incidentId":"99353b3a-794c-4d8a-ac01-df3f109900ed","incidentCommentId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.message | string | Response message |
properties.createdTimeUtc | string | Output field: properties.createdTimeUtc |
properties.lastModifiedTimeUtc | string | Output field: properties.lastModifiedTimeUtc |
properties.author | object | Output field: properties.author |
properties.author.objectId | string | Unique identifier |
properties.author.email | string | Output field: properties.author.email |
properties.author.userPrincipalName | string | Name of the resource |
properties.author.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-correlation-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-routing-request-id":"CENTRALINDIA:20240118T092209Z:aa4...
Get Saved Searches
Retrieve a specific saved search from Microsoft Azure Sentinel using resource group, search ID, subscription, and workspace name.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourcegroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/savedSearches/{{savedSearchId}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.resourceGroupName | string | Required | Parameters for the Get Saved Searches action |
path_parameters.savedSearchId | string | Required | Parameters for the Get Saved Searches action |
path_parameters.subscriptionId | string | Required | Parameters for the Get Saved Searches action |
path_parameters.workspaceName | string | Required | Parameters for the Get Saved Searches action |
parameters.api-version | string | Required | Parameters for the Get Saved Searches action |
Input Example
{"parameters":{"api-version":"2020-08-01"},"path_parameters":{"resourceGroupName":"","savedSearchId":"00000000-0000-0000-0000-00000000000","subscriptionId":"Azure subscription 1","workspaceName":""}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.category | string | Output field: properties.category |
properties.displayName | string | Name of the resource |
properties.functionAlias | string | Output field: properties.functionAlias |
properties.functionParameters | string | Parameters for the Get Saved Searches action |
properties.query | string | Output field: properties.query |
properties.version | number | Output field: properties.version |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Content-Type":"application/json; charset=utf-8","Expires":"-1","x-ms-failure-cause":"gateway","x-ms-request-id":"54b36bb1-0d41-45b8-a8ba-6f4552f3c8fe","x-ms-correlation-request-id":"54b36bb1-0d41-45b8-a8ba-6f4552f3c8fe","x-ms-routing-request-id":"JIOINDIACENTRAL:20230810T090934Z:54b36bb1-0d41-45b8-a8ba-6f4552f3c8fe","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Content-Type-Options":"nos...
List Alert Rules
Retrieve all alert rules from a specified Microsoft Azure Sentinel workspace using subscription ID, resource group, and workspace name.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/alertRules
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.api-version | string | Required | The API version to use for this operation. |
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$. |
Input Example
{"parameters":{"api-version":"2024-03-01"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.type | string | Type of the resource |
value.kind | string | Value for the parameter |
value.etag | string | Value for the parameter |
value.properties | object | Value for the parameter |
value.properties.displayName | string | Name of the resource |
value.properties.description | string | Value for the parameter |
value.properties.alertRuleTemplateName | string | Name of the resource |
value.properties.tactics | array | Value for the parameter |
value.properties.severity | string | Value for the parameter |
value.properties.enabled | boolean | Value for the parameter |
value.properties.lastModifiedUtc | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-store, no-cache","Pragma":"no-cache","Content-Type":"application/json; charset=utf-8","Expires":"-1","Strict-Transport-Security":"max-age=31536000; includeSubDomains","X-Content-Type-Options":"nosniff","P3P":"CP=\"DSP CUR OTPi IND OTRi ONL FIN\"","x-ms-request-id":"f04749a8-b1d4-42ed-a64d-7c0cab024e00","x-ms-ests-server":"2.1.18261.3 - EUS ProdSlices","x-ms-srs":"1.P","X-XSS-Protection":"0","Set-Cookie":"fpc=AjlweEqE3N5AsDykcUumbB5D3sW4A...
List By Workspace Saved Searches
Retrieve all saved searches within a Log Analytics Workspace in Microsoft Azure Sentinel. Requires resource group, subscription ID, workspace name, and API version.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourcegroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/savedSearches
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.resourceGroupName | string | Required | Parameters for the List By Workspace Saved Searches action |
path_parameters.subscriptionId | string | Required | Parameters for the List By Workspace Saved Searches action |
path_parameters.workspaceName | string | Required | Parameters for the List By Workspace Saved Searches action |
parameters.api-version | string | Required | Parameters for the List By Workspace Saved Searches action |
Input Example
{"parameters":{"api-version":"2020-08-01"},"path_parameters":{"resourceGroupName":"","subscriptionId":"Azure subscription 1","workspaceName":""}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.etag | string | Value for the parameter |
value.properties | object | Value for the parameter |
value.properties.displayName | string | Name of the resource |
value.properties.category | string | Value for the parameter |
value.properties.query | string | Value for the parameter |
value.properties.version | number | Value for the parameter |
value.name | string | Name of the resource |
value.type | string | Type of the resource |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","x-ms-ratelimit-remaining-subscription-reads":"11999","Request-Context":"appId=cid-v1:e6336c63-aab2-45f0-996a-e5dbab2a1508","X-Content-Type-Options":"nosniff","Strict-Transport-Security":"max-age=31536000; includeSubDomains","Access-Control-Allow-Origin":"*","X-Powered...
List Incident Alerts
Retrieve all alerts linked to a specific incident in Microsoft Azure Sentinel using subscription ID, resource group, workspace name, and incident ID.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/alerts
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.type | string | Type of the resource |
value.kind | string | Value for the parameter |
value.properties | object | Value for the parameter |
value.properties.systemAlertId | string | Unique identifier |
value.properties.tactics | array | Value for the parameter |
value.properties.tactics.file_name | string | Name of the resource |
value.properties.tactics.file | string | Value for the parameter |
value.properties.alertDisplayName | string | Name of the resource |
value.properties.description | string | Value for the parameter |
value.properties.confidenceLevel | string | Unique identifier |
value.properties.severity | string | Value for the parameter |
value.properties.vendorName | string | Name of the resource |
value.properties.productName | string | Name of the resource |
value.properties.productComponentName | string | Name of the resource |
value.properties.alertType | string | Type of the resource |
value.properties.processingEndTime | string | Value for the parameter |
value.properties.status | string | Status value |
value.properties.endTimeUtc | string | Value for the parameter |
value.properties.startTimeUtc | string | Value for the parameter |
value.properties.timeGenerated | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"8745ade4-8c1e-4c0b-beec-2969c4a779e9","x-ms-correlation-request-id":"8745ade4-8c1e-4c0b-beec-2969c4a779e9","x-ms-routing-request-id":"SOUTHINDIA:20230729T111826Z:8745a...
List Incident Bookmarks
Retrieve all bookmarks linked to an incident in Microsoft Azure Sentinel using subscription, resource group, workspace, and incident IDs.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/bookmarks
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.type | string | Type of the resource |
value.kind | string | Value for the parameter |
value.properties | object | Value for the parameter |
value.properties.displayName | string | Name of the resource |
value.properties.created | string | Value for the parameter |
value.properties.updated | string | Value for the parameter |
value.properties.createdBy | object | Value for the parameter |
value.properties.createdBy.objectId | string | Unique identifier |
value.properties.createdBy.email | string | Value for the parameter |
value.properties.createdBy.name | string | Name of the resource |
value.properties.updatedBy | object | Value for the parameter |
value.properties.updatedBy.objectId | string | Unique identifier |
value.properties.updatedBy.email | string | Value for the parameter |
value.properties.updatedBy.name | string | Name of the resource |
value.properties.eventTime | string | Value for the parameter |
value.properties.labels | array | Value for the parameter |
value.properties.labels.file_name | string | Name of the resource |
value.properties.labels.file | string | Value for the parameter |
value.properties.query | string | Value for the parameter |
value.properties.queryResult | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"fa5a78c9-cc33-4e7e-9aa1-800086279fbd","x-ms-correlation-request-id":"fa5a78c9-cc33-4e7e-9aa1-800086279fbd","x-ms-routing-request-id":"SOUTHINDIA:20230729T112006Z:fa5a7...
List Incident Comments
Retrieve all comments for a specific incident in Microsoft Azure Sentinel using subscriptionId, resourceGroupName, workspaceName, and incidentId.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/comments
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | Parameters for the List Incident Comments action |
path_parameters.resourceGroupName | string | Required | Parameters for the List Incident Comments action |
path_parameters.workspaceName | string | Required | Parameters for the List Incident Comments action |
path_parameters.incidentId | string | Required | Parameters for the List Incident Comments action |
parameters.api-version | string | Required | Parameters for the List Incident Comments action |
parameters.$filter | string | Optional | Parameters for the List Incident Comments action |
parameters.$orderby | string | Optional | Parameters for the List Incident Comments action |
parameters.$skipToken | string | Optional | Parameters for the List Incident Comments action |
parameters.$top | number | Optional | Parameters for the List Incident Comments action |
Input Example
{"parameters":{"api-version":"2023-02-01","$filter":"string","$orderby":"string","$skipToken":"string","$top":10},"path_parameters":{"subscriptionId":"38d4cde9-8ef2-4c61-bc61-7fa8658ab74b","resourceGroupName":"test","workspaceName":"swimlaneazuresentinel","incidentId":"99353b3a-794c-4d8a-ac01-df3f109900ed"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.type | string | Type of the resource |
value.etag | string | Value for the parameter |
value.properties | object | Value for the parameter |
value.properties.message | string | Value for the parameter |
value.properties.createdTimeUtc | string | Value for the parameter |
value.properties.lastModifiedTimeUtc | string | Value for the parameter |
value.properties.author | object | Value for the parameter |
value.properties.author.objectId | string | Unique identifier |
value.properties.author.email | string | Value for the parameter |
value.properties.author.userPrincipalName | string | Name of the resource |
value.properties.author.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-correlation-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-routing-request-id":"CENTRALINDIA:20240118T092209Z:aa4...
List Incident Entities
Retrieve all entities linked to a specific incident in Microsoft Azure Sentinel using subscriptionId, resourceGroupName, workspaceName, and incidentId.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/entities
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
path_parameters.incidentId | string | Required | Incident ID |
parameters.api-version | string | Required | The API version to use for this action. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name","incidentId":"string"},"parameters":{"api-version":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
entities | array | Output field: entities |
entities.id | string | Unique identifier |
entities.name | string | Name of the resource |
entities.type | string | Type of the resource |
entities.kind | string | Output field: entities.kind |
entities.properties | object | Output field: entities.properties |
entities.properties.friendlyName | string | Name of the resource |
entities.properties.accountName | string | Name of the resource |
entities.properties.ntDomain | string | Output field: entities.properties.ntDomain |
metaData | array | Response data |
metaData.entityKind | string | Response data |
metaData.count | number | Response data |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"48c22610-cfa7-4ba0-9315-fd8bbd2aadba","x-ms-correlation-request-id":"48c22610-cfa7-4ba0-9315-fd8bbd2aadba","x-ms-routing-request-id":"SOUTHINDIA:20230729T122235Z:48c22...
List Incidents
Retrieve all incidents from Microsoft Azure Sentinel using subscription ID, resource group, and workspace name.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | The ID of the target subscription. |
path_parameters.resourceGroupName | string | Required | The name of the resource group. The name is case insensitive. |
path_parameters.workspaceName | string | Required | The name of the workspace. Regex pattern - ^[A-Za-z0-9][A-Za-z0-9-]+[A-Za-z0-9]$ |
parameters.api-version | string | Required | The API version to use for this action. |
parameters.$filter | string | Optional | Filter the results, based on a Boolean condition. |
parameters.$orderby | string | Optional | Sort the results. |
parameters.$skipToken | string | Optional | Skiptoken is only used if a previous operation returned a partial result. If a previous response contains a nextLink element, the value of the nextLink element will include a skiptoken parameter that specifies a starting point to use for subsequent calls. |
parameters.$top | number | Optional | Return only the first n results. |
Input Example
{"path_parameters":{"subscriptionId":"string","resourceGroupName":"Example Name","workspaceName":"Example Name"},"parameters":{"api-version":"string","$filter":"string","$orderby":"string","$skipToken":"string","$top":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.etag | string | Value for the parameter |
value.type | string | Type of the resource |
value.properties | object | Value for the parameter |
value.properties.title | string | Value for the parameter |
value.properties.description | string | Value for the parameter |
value.properties.severity | string | Value for the parameter |
value.properties.status | string | Status value |
value.properties.owner | object | Value for the parameter |
value.properties.owner.objectId | object | Unique identifier |
value.properties.owner.email | object | Value for the parameter |
value.properties.owner.assignedTo | object | Value for the parameter |
value.properties.owner.userPrincipalName | object | Name of the resource |
value.properties.labels | array | Value for the parameter |
value.properties.labels.file_name | string | Name of the resource |
value.properties.labels.file | string | Value for the parameter |
value.properties.firstActivityTimeUtc | string | Value for the parameter |
value.properties.lastActivityTimeUtc | string | Value for the parameter |
value.properties.lastModifiedTimeUtc | string | Value for the parameter |
value.properties.createdTimeUtc | string | Value for the parameter |
value.properties.incidentNumber | number | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-reads":"11999","x-ms-request-id":"b0182057-82a0-4253-aa3c-5be0c8ab9809","x-ms-correlation-request-id":"b0182057-82a0-4253-aa3c-5be0c8ab9809","x-ms-routing-request-id":"SOUTHINDIA:20230729T110918Z:b0182057-82a0-4...
Run Analytics Query
Execute an analytics query in Microsoft Azure Sentinel using workspace ID, query string, and optional API version.
Endpoint
- URL: /{{apiVersion}}/workspaces/{{workspaceId}}/query
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.workspaceId | string | Required | Parameters for the Run Analytics Query action |
path_parameters.apiVersion | string | Required | The API version to use for this action. |
query | string | Optional | The Analytics query. |
timespan | string | Optional | The timespan over which to query data. This is an ISO8601 time period value. This timespan is applied in addition to any that are specified in the query expression. |
workspaces | array | Optional | The workspaces to query. |
Input Example
{"path_parameters":{"workspaceId":"string","apiVersion":"string"},"query":"string","timespan":"string","workspaces":["string"]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
tables | array | Output field: tables |
tables.name | string | Name of the resource |
tables.columns | array | Output field: tables.columns |
tables.columns.name | string | Name of the resource |
tables.columns.type | string | Type of the resource |
tables.rows | array | Output field: tables.rows |
Output Example
{"status_code":200,"response_headers":{"Date":"Fri, 11 Aug 2023 03:08:43 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","via":"1.1 draft-oms-74c8fb9684-6rv8g","X-Content-Type-Options":"nosniff","Access-Control-Allow-Origin":"*","Access-Control-Expose-Headers":"Retry-After,Age,WWW-Authenticate,x-resource-identities,x-ms-status-location","Vary":"Accept-Encoding","Content-Encoding":"gzip","Strict-Transport-Security":"max-age=15724800; i...
Update Incident Comment
Create or update an incident comment in Microsoft Azure Sentinel using identifiers like subscriptionId, resourceGroupName, workspaceName, incidentId, and incidentCommentId.
Endpoint
- URL: /subscriptions/{{subscriptionId}}/resourceGroups/{{resourceGroupName}}/providers/Microsoft.OperationalInsights/workspaces/{{workspaceName}}/providers/Microsoft.SecurityInsights/incidents/{{incidentId}}/comments/{{incidentCommentId}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.subscriptionId | string | Required | Parameters for the Update Incident Comment action |
path_parameters.resourceGroupName | string | Required | Parameters for the Update Incident Comment action |
path_parameters.workspaceName | string | Required | Parameters for the Update Incident Comment action |
path_parameters.incidentId | string | Required | Parameters for the Update Incident Comment action |
path_parameters.incidentCommentId | string | Required | Parameters for the Update Incident Comment action |
parameters.api-version | string | Required | Parameters for the Update Incident Comment action |
properties | object | Optional | Parameter for Update Incident Comment |
properties.message | string | Required | Response message |
etag | string | Optional | Parameter for Update Incident Comment |
Input Example
{"parameters":{"api-version":"2023-02-01"},"json_body":{"properties":{"message":"Some Message"},"etag":"String"},"path_parameters":{"subscriptionId":"38d4cde9-8ef2-4c61-bc61-7fa8658ab74b","resourceGroupName":"test","workspaceName":"swimlaneazuresentinel","incidentId":"99353b3a-794c-4d8a-ac01-df3f109900ed","incidentCommentId":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
name | string | Name of the resource |
type | string | Type of the resource |
etag | string | Output field: etag |
properties | object | Output field: properties |
properties.message | string | Response message |
properties.createdTimeUtc | string | Output field: properties.createdTimeUtc |
properties.lastModifiedTimeUtc | string | Output field: properties.lastModifiedTimeUtc |
properties.author | object | Output field: properties.author |
properties.author.objectId | string | Unique identifier |
properties.author.email | string | Output field: properties.author.email |
properties.author.userPrincipalName | string | Name of the resource |
properties.author.name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Cache-Control":"no-cache","Pragma":"no-cache","Transfer-Encoding":"chunked","Content-Type":"application/json; charset=utf-8","Content-Encoding":"gzip","Expires":"-1","Vary":"Accept-Encoding","Server":"Kestrel","x-ms-ratelimit-remaining-subscription-resource-requests":"499","x-ms-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-correlation-request-id":"aa473e1f-78ce-4466-a0c6-f14359c755a2","x-ms-routing-request-id":"CENTRALINDIA:20240118T092209Z:aa4...
Response Headers
Header | Description | Example |
|---|---|---|
Access-Control-Allow-Origin | HTTP response header: Access-Control-Allow-Origin | * |
Access-Control-Expose-Headers | HTTP response header: Access-Control-Expose-Headers | Retry-After,Age,WWW-Authenticate,x-resource-identities,x-ms-status-location |
Cache-Control | Directives for caching mechanisms | no-cache |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Length | The length of the response body in bytes | 695 |
Content-Type | The media type of the resource | application/json; charset=utf-8 |
Date | The date and time at which the message was originated | Sat, 29 Jul 2023 11:09:17 GMT |
Expires | The date/time after which the response is considered stale | -1 |
P3P | HTTP response header: P3P | CP="DSP CUR OTPi IND OTRi ONL FIN" |
Pragma | HTTP response header: Pragma | no-cache |
Request-Context | HTTP response header: Request-Context | appId=cid-v1:e6336c63-aab2-45f0-996a-e5dbab2a1508 |
Server | Information about the software used by the origin server | Kestrel |
Set-Cookie | HTTP response header: Set-Cookie | fpc=AjlweEqE3N5AsDykcUumbB5D3sW4AQAAAK9y-90OAAAA; expires=Fri, 12-Jul-2024 10:42:55 GMT; path=/; secure; HttpOnly; SameSite=None, x-ms-gateway-slice=estsfd; path=/; secure; samesite=none; httponly, stsservicecookie=estsfd; path=/; secure; samesite=none; httponly |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |
via | HTTP response header: via | 1.1 draft-oms-74c8fb9684-6rv8g |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
x-ms-correlation-request-id | HTTP response header: x-ms-correlation-request-id | 54b36bb1-0d41-45b8-a8ba-6f4552f3c8fe |
x-ms-ests-server | HTTP response header: x-ms-ests-server | 2.1.18261.3 - EUS ProdSlices |
x-ms-failure-cause | HTTP response header: x-ms-failure-cause | gateway |
x-ms-ratelimit-remaining-subscription-deletes | HTTP response header: x-ms-ratelimit-remaining-subscription-deletes | 14999 |
x-ms-ratelimit-remaining-subscription-reads | HTTP response header: x-ms-ratelimit-remaining-subscription-reads | 11999 |
x-ms-ratelimit-remaining-subscription-resource-requests | HTTP response header: x-ms-ratelimit-remaining-subscription-resource-requests | 499 |
x-ms-ratelimit-remaining-subscription-writes | HTTP response header: x-ms-ratelimit-remaining-subscription-writes | 1199 |
x-ms-request-id | HTTP response header: x-ms-request-id | 54b36bb1-0d41-45b8-a8ba-6f4552f3c8fe |
x-ms-routing-request-id | HTTP response header: x-ms-routing-request-id | CENTRALINDIA:20240118T092209Z:aa473e1f-78ce-4466-a0c6-f14359c755a2 |
x-ms-srs | HTTP response header: x-ms-srs | 1.P |
X-Powered-By | HTTP response header: X-Powered-By | ASP.NET |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 0 |