Details

This atomic belongs to the Microsoft Sentinel atomic group.

This atomic fetches incidents from Microsoft Sentinel.

Target: Microsoft Sentinel

Steps:

  • Build the query string
  • Fetch incidents list
  • Check if the request was successful:
    • If it was, extract list and set the output variable
    • If it wasn't, output an error

More information about this API: https://learn.microsoft.com/en-us/rest/api/securityinsights/incidents/list?view=rest-securityinsights-2025-06-01&tabs=HTTP

About
Authorship
Cisco Managed