Automation Rule Property Condition Supported Property
The property to evaluate in an automation rule property condition.
Entries
The title of the incident
The description of the incident
The severity of the incident
The status of the incident
The related Analytic rule ids of the incident
The tactics of the incident
The labels of the incident
The provider name of the incident
The update source of the incident
The account Azure Active Directory tenant id
The account Azure Active Directory user id
The account name
The account NetBIOS domain name
The account Azure Active Directory Passport User ID
The account security identifier
The account unique identifier
The account user principal name suffix
The name of the product of the alert
The analytic rule ids of the alert
The Azure resource id
The Azure resource subscription id
The cloud application identifier
The cloud application name
The dns record domain name
The file directory full path
The file hash value
The host Azure resource id
The host NetBIOS name
The host NT domain
The host operating system
"The IoT device id
The IoT device name
The IoT device type
The IoT device vendor
The IoT device model
The IoT device operating system
The mailbox display name
The mailbox primary address
The mailbox user principal name
The mail message delivery action
The mail message delivery location
The mail message recipient
The mail message sender IP address
The mail message subject
The mail message P1 sender
The mail message P2 sender
The malware category
The malware name
The process execution command line
The registry key path
The registry key value in string formatted representation
Properties
Functions
Returns the enum constant of this type with the specified name. The string must match exactly an identifier used to declare an enum constant in this type. (Extraneous whitespace characters are not permitted.)
Returns an array containing the constants of this enum type, in the order they're declared.