Skip to main content

incident_relations

Creates, updates, deletes, gets or lists a incident_relations resource.

Overview

Nameincident_relations
TypeResource
Idazure.sentinel.incident_relations

Fields

NameDatatypeDescription
etagtextEtag of the azure resource
incidentIdtextfield from the properties object
related_resource_idtextfield from the properties object
related_resource_kindtextfield from the properties object
related_resource_nametextfield from the properties object
related_resource_typetextfield from the properties object
relationNametextfield from the properties object
resourceGroupNametextfield from the properties object
subscriptionIdtextfield from the properties object
workspaceNametextfield from the properties object

Methods

NameAccessible byRequired ParamsDescription
getSELECTincidentId, relationName, resourceGroupName, subscriptionId, workspaceNameGets a relation for a given incident.
listSELECTincidentId, resourceGroupName, subscriptionId, workspaceNameGets all relations for a given incident.
create_or_updateINSERTincidentId, relationName, resourceGroupName, subscriptionId, workspaceNameCreates or updates a relation for a given incident.
deleteDELETEincidentId, relationName, resourceGroupName, subscriptionId, workspaceNameDeletes a relation for a given incident.

SELECT examples

Gets all relations for a given incident.

SELECT
etag,
incidentId,
related_resource_id,
related_resource_kind,
related_resource_name,
related_resource_type,
relationName,
resourceGroupName,
subscriptionId,
workspaceName
FROM azure.sentinel.vw_incident_relations
WHERE incidentId = '{{ incidentId }}'
AND resourceGroupName = '{{ resourceGroupName }}'
AND subscriptionId = '{{ subscriptionId }}'
AND workspaceName = '{{ workspaceName }}';

INSERT example

Use the following StackQL query and manifest file to create a new incident_relations resource.

/*+ create */
INSERT INTO azure.sentinel.incident_relations (
incidentId,
relationName,
resourceGroupName,
subscriptionId,
workspaceName,
etag,
properties
)
SELECT
'{{ incidentId }}',
'{{ relationName }}',
'{{ resourceGroupName }}',
'{{ subscriptionId }}',
'{{ workspaceName }}',
'{{ etag }}',
'{{ properties }}'
;

DELETE example

Deletes the specified incident_relations resource.

/*+ delete */
DELETE FROM azure.sentinel.incident_relations
WHERE incidentId = '{{ incidentId }}'
AND relationName = '{{ relationName }}'
AND resourceGroupName = '{{ resourceGroupName }}'
AND subscriptionId = '{{ subscriptionId }}'
AND workspaceName = '{{ workspaceName }}';