Skip to main content

bookmarks

Creates, updates, deletes, gets or lists a bookmarks resource.

Overview

Namebookmarks
TypeResource
Idazure.sentinel.bookmarks

Fields

NameDatatypeDescription
bookmarkIdtextfield from the properties object
createdtextfield from the properties object
created_bytextfield from the properties object
display_nametextfield from the properties object
etagtextEtag of the azure resource
event_timetextfield from the properties object
incident_infotextfield from the properties object
labelstextfield from the properties object
notestextfield from the properties object
querytextfield from the properties object
query_end_timetextfield from the properties object
query_resulttextfield from the properties object
query_start_timetextfield from the properties object
resourceGroupNametextfield from the properties object
subscriptionIdtextfield from the properties object
updatedtextfield from the properties object
updated_bytextfield from the properties object
workspaceNametextfield from the properties object

Methods

NameAccessible byRequired ParamsDescription
getSELECTbookmarkId, resourceGroupName, subscriptionId, workspaceNameGets a bookmark.
listSELECTresourceGroupName, subscriptionId, workspaceNameGets all bookmarks.
create_or_updateINSERTbookmarkId, resourceGroupName, subscriptionId, workspaceNameCreates or updates the bookmark.
deleteDELETEbookmarkId, resourceGroupName, subscriptionId, workspaceNameDelete the bookmark.

SELECT examples

Gets all bookmarks.

SELECT
bookmarkId,
created,
created_by,
display_name,
etag,
event_time,
incident_info,
labels,
notes,
query,
query_end_time,
query_result,
query_start_time,
resourceGroupName,
subscriptionId,
updated,
updated_by,
workspaceName
FROM azure.sentinel.vw_bookmarks
WHERE resourceGroupName = '{{ resourceGroupName }}'
AND subscriptionId = '{{ subscriptionId }}'
AND workspaceName = '{{ workspaceName }}';

INSERT example

Use the following StackQL query and manifest file to create a new bookmarks resource.

/*+ create */
INSERT INTO azure.sentinel.bookmarks (
bookmarkId,
resourceGroupName,
subscriptionId,
workspaceName,
etag,
properties
)
SELECT
'{{ bookmarkId }}',
'{{ resourceGroupName }}',
'{{ subscriptionId }}',
'{{ workspaceName }}',
'{{ etag }}',
'{{ properties }}'
;

DELETE example

Deletes the specified bookmarks resource.

/*+ delete */
DELETE FROM azure.sentinel.bookmarks
WHERE bookmarkId = '{{ bookmarkId }}'
AND resourceGroupName = '{{ resourceGroupName }}'
AND subscriptionId = '{{ subscriptionId }}'
AND workspaceName = '{{ workspaceName }}';