Skip to main content

incidents_entities

Creates, updates, deletes, gets or lists a incidents_entities resource.

Overview

Nameincidents_entities
TypeResource
Idazure.sentinel.incidents_entities

Fields

NameDatatypeDescription
entitiesarrayArray of the incident related entities.
metaDataarrayThe metadata from the incident related entities results.

Methods

NameAccessible byRequired ParamsDescription
listSELECTincidentId, resourceGroupName, subscriptionId, workspaceNameGets all entities for an incident.

SELECT examples

Gets all entities for an incident.

SELECT
entities,
metaData
FROM azure.sentinel.incidents_entities
WHERE incidentId = '{{ incidentId }}'
AND resourceGroupName = '{{ resourceGroupName }}'
AND subscriptionId = '{{ subscriptionId }}'
AND workspaceName = '{{ workspaceName }}';