SecurityinsightsFunctions

Functions

Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getAADDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetAADDataConnectorResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getAATPDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetAATPDataConnectorResult
Link copied to clipboard

Gets the action of alert rule. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getAction(argument: suspend GetActionPlainArgsBuilder.() -> Unit): GetActionResult
suspend fun getAction(actionId: String, resourceGroupName: String, ruleId: String, workspaceName: String): GetActionResult
Link copied to clipboard

Gets an entity query. Uses Azure REST API version 2023-06-01-preview.

suspend fun getActivityCustomEntityQuery(entityQueryId: String, resourceGroupName: String, workspaceName: String): GetActivityCustomEntityQueryResult
Link copied to clipboard

Gets a setting. Uses Azure REST API version 2023-06-01-preview.

suspend fun getAnomalies(resourceGroupName: String, settingsName: String, workspaceName: String): GetAnomaliesResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getASCDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetASCDataConnectorResult
Link copied to clipboard

Gets the automation rule. Uses Azure REST API version 2023-02-01. Other available API versions: 2019-01-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getAutomationRule(automationRuleId: String, resourceGroupName: String, workspaceName: String): GetAutomationRuleResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getAwsCloudTrailDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetAwsCloudTrailDataConnectorResult
Link copied to clipboard

Gets a bookmark. Uses Azure REST API version 2023-02-01. Other available API versions: 2019-01-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getBookmark(argument: suspend GetBookmarkPlainArgsBuilder.() -> Unit): GetBookmarkResult
suspend fun getBookmark(bookmarkId: String, resourceGroupName: String, workspaceName: String): GetBookmarkResult
Link copied to clipboard

Gets a bookmark relation. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2019-01-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getBookmarkRelation(bookmarkId: String, relationName: String, resourceGroupName: String, workspaceName: String): GetBookmarkRelationResult
Link copied to clipboard

Gets Business Application Agent. Uses Azure REST API version 2024-04-01-preview. Other available API versions: 2024-10-01-preview, 2025-01-01-preview.

suspend fun getBusinessApplicationAgent(agentResourceName: String, resourceGroupName: String, workspaceName: String): GetBusinessApplicationAgentResult
Link copied to clipboard

Gets an installed packages by its id. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getContentPackage(packageId: String, resourceGroupName: String, workspaceName: String): GetContentPackageResult
Link copied to clipboard

Gets a template byt its identifier. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getContentTemplate(resourceGroupName: String, templateId: String, workspaceName: String): GetContentTemplateResult
Link copied to clipboard

Gets a data connector definition. Uses Azure REST API version 2023-07-01-preview.

suspend fun getCustomizableConnectorDefinition(dataConnectorDefinitionName: String, resourceGroupName: String, workspaceName: String): GetCustomizableConnectorDefinitionResult
Link copied to clipboard

Timeline for an entity. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2019-01-01-preview, 2021-09-01-preview, 2021-10-01-preview, 2022-01-01-preview, 2022-04-01-preview, 2022-05-01-preview, 2022-06-01-preview, 2022-07-01-preview, 2022-08-01-preview, 2022-09-01-preview, 2022-10-01-preview, 2022-11-01-preview, 2022-12-01-preview, 2023-02-01-preview, 2023-03-01-preview, 2023-04-01-preview, 2023-05-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getEntitiesGetTimeline(endTime: String, entityId: String, kinds: List<Either<String, EntityTimelineKind>>? = null, numberOfBucket: Int? = null, resourceGroupName: String, startTime: String, workspaceName: String): GetEntitiesGetTimelineResult
Link copied to clipboard

Gets a setting. Uses Azure REST API version 2023-06-01-preview.

suspend fun getEntityAnalytics(resourceGroupName: String, settingsName: String, workspaceName: String): GetEntityAnalyticsResult
Link copied to clipboard

Execute Insights for an entity. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2019-01-01-preview, 2021-09-01-preview, 2021-10-01-preview, 2022-01-01-preview, 2022-04-01-preview, 2022-05-01-preview, 2022-06-01-preview, 2022-07-01-preview, 2022-08-01-preview, 2022-09-01-preview, 2022-10-01-preview, 2022-11-01-preview, 2022-12-01-preview, 2023-02-01-preview, 2023-03-01-preview, 2023-04-01-preview, 2023-05-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getEntityInsights(addDefaultExtendedTimeRange: Boolean? = null, endTime: String, entityId: String, insightQueryIds: List<String>? = null, resourceGroupName: String, startTime: String, workspaceName: String): GetEntityInsightsResult
Link copied to clipboard

Gets a setting. Uses Azure REST API version 2023-06-01-preview.

suspend fun getEyesOn(argument: suspend GetEyesOnPlainArgsBuilder.() -> Unit): GetEyesOnResult
suspend fun getEyesOn(resourceGroupName: String, settingsName: String, workspaceName: String): GetEyesOnResult
Link copied to clipboard

Gets a file import. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getFileImport(fileImportId: String, resourceGroupName: String, workspaceName: String): GetFileImportResult
Link copied to clipboard

Gets the alert rule. Uses Azure REST API version 2023-02-01.

suspend fun getFusionAlertRule(resourceGroupName: String, ruleId: String, workspaceName: String): GetFusionAlertRuleResult
Link copied to clipboard
suspend fun getHunt(argument: GetHuntPlainArgs): GetHuntResult

Gets a hunt, without relations and comments. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getHunt(argument: suspend GetHuntPlainArgsBuilder.() -> Unit): GetHuntResult
suspend fun getHunt(huntId: String, resourceGroupName: String, workspaceName: String): GetHuntResult
Link copied to clipboard

Gets a hunt comment Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getHuntComment(huntCommentId: String, huntId: String, resourceGroupName: String, workspaceName: String): GetHuntCommentResult
Link copied to clipboard

Gets a hunt relation Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getHuntRelation(huntId: String, huntRelationId: String, resourceGroupName: String, workspaceName: String): GetHuntRelationResult
Link copied to clipboard

Gets a given incident. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-02-01-preview, 2023-03-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getIncident(argument: suspend GetIncidentPlainArgsBuilder.() -> Unit): GetIncidentResult
suspend fun getIncident(incidentId: String, resourceGroupName: String, workspaceName: String): GetIncidentResult
Link copied to clipboard

Gets a comment for a given incident. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getIncidentComment(incidentCommentId: String, incidentId: String, resourceGroupName: String, workspaceName: String): GetIncidentCommentResult
Link copied to clipboard

Gets a relation for a given incident. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getIncidentRelation(incidentId: String, relationName: String, resourceGroupName: String, workspaceName: String): GetIncidentRelationResult
Link copied to clipboard

Gets an incident task. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getIncidentTask(incidentId: String, incidentTaskId: String, resourceGroupName: String, workspaceName: String): GetIncidentTaskResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getMCASDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetMCASDataConnectorResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getMDATPDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetMDATPDataConnectorResult
Link copied to clipboard

Get a Metadata. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-02-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getMetadata(argument: suspend GetMetadataPlainArgsBuilder.() -> Unit): GetMetadataResult
suspend fun getMetadata(metadataName: String, resourceGroupName: String, workspaceName: String): GetMetadataResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getOfficeDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetOfficeDataConnectorResult
Link copied to clipboard

Gets the alert rule. Uses Azure REST API version 2023-02-01.

suspend fun getScheduledAlertRule(resourceGroupName: String, ruleId: String, workspaceName: String): GetScheduledAlertRuleResult
Link copied to clipboard

Get Sentinel onboarding state Uses Azure REST API version 2023-02-01. Other available API versions: 2021-03-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getSentinelOnboardingState(resourceGroupName: String, sentinelOnboardingStateName: String, workspaceName: String): GetSentinelOnboardingStateResult
Link copied to clipboard

Gets a source control byt its identifier. Uses Azure REST API version 2023-05-01-preview. Other available API versions: 2021-03-01-preview.

suspend fun getSourceControl(resourceGroupName: String, sourceControlId: String, workspaceName: String): GetSourceControlResult
Link copied to clipboard

Gets the system. Uses Azure REST API version 2024-04-01-preview. Other available API versions: 2024-10-01-preview, 2025-01-01-preview.

suspend fun getSystem(argument: suspend GetSystemPlainArgsBuilder.() -> Unit): GetSystemResult
suspend fun getSystem(agentResourceName: String, resourceGroupName: String, systemResourceName: String, workspaceName: String): GetSystemResult
Link copied to clipboard

View a threat intelligence indicator by name. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-04-01, 2021-09-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getThreatIntelligenceIndicator(name: String, resourceGroupName: String, workspaceName: String): GetThreatIntelligenceIndicatorResult
Link copied to clipboard

Gets a data connector. Uses Azure REST API version 2023-02-01.

suspend fun getTIDataConnector(dataConnectorId: String, resourceGroupName: String, workspaceName: String): GetTIDataConnectorResult
Link copied to clipboard
suspend fun getUeba(argument: GetUebaPlainArgs): GetUebaResult

Gets a setting. Uses Azure REST API version 2023-06-01-preview.

suspend fun getUeba(argument: suspend GetUebaPlainArgsBuilder.() -> Unit): GetUebaResult
suspend fun getUeba(resourceGroupName: String, settingsName: String, workspaceName: String): GetUebaResult
Link copied to clipboard

Get a watchlist, without its watchlist items. Uses Azure REST API version 2023-02-01. Other available API versions: 2019-01-01-preview, 2021-03-01-preview, 2021-04-01, 2021-10-01-preview, 2022-01-01-preview, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getWatchlist(resourceGroupName: String, watchlistAlias: String, workspaceName: String): GetWatchlistResult
Link copied to clipboard

Get a watchlist item. Uses Azure REST API version 2023-02-01. Other available API versions: 2021-04-01, 2023-06-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-11-01, 2023-12-01-preview, 2024-01-01-preview, 2024-03-01, 2024-04-01-preview, 2024-09-01, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun getWatchlistItem(resourceGroupName: String, watchlistAlias: String, watchlistItemId: String, workspaceName: String): GetWatchlistItemResult
Link copied to clipboard

Gets a workspace manager assignment Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getWorkspaceManagerAssignment(resourceGroupName: String, workspaceManagerAssignmentName: String, workspaceName: String): GetWorkspaceManagerAssignmentResult
Link copied to clipboard

Gets a workspace manager configuration Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getWorkspaceManagerConfiguration(resourceGroupName: String, workspaceManagerConfigurationName: String, workspaceName: String): GetWorkspaceManagerConfigurationResult
Link copied to clipboard

Gets a workspace manager group Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getWorkspaceManagerGroup(resourceGroupName: String, workspaceManagerGroupName: String, workspaceName: String): GetWorkspaceManagerGroupResult
Link copied to clipboard

Gets a workspace manager member Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun getWorkspaceManagerMember(resourceGroupName: String, workspaceManagerMemberName: String, workspaceName: String): GetWorkspaceManagerMemberResult
Link copied to clipboard

Get geodata for a single IP address Uses Azure REST API version 2024-01-01-preview. Other available API versions: 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun listGeodataByIp(enrichmentType: String, ipAddress: String? = null, resourceGroupName: String, workspaceName: String): ListGeodataByIpResult
Link copied to clipboard

Gets a list of repositories metadata. Uses Azure REST API version 2023-06-01-preview. Other available API versions: 2021-03-01-preview, 2021-09-01-preview, 2021-10-01-preview, 2022-01-01-preview, 2022-04-01-preview, 2022-05-01-preview, 2022-06-01-preview, 2022-07-01-preview, 2022-08-01-preview, 2022-09-01-preview, 2022-10-01-preview, 2022-11-01-preview, 2022-12-01-preview, 2023-02-01-preview, 2023-03-01-preview, 2023-04-01-preview, 2023-05-01-preview, 2023-07-01-preview, 2023-08-01-preview, 2023-09-01-preview, 2023-10-01-preview, 2023-12-01-preview, 2024-01-01-preview, 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview, 2025-03-01.

suspend fun listSourceControlRepositories(resourceGroupName: String, workspaceName: String): ListSourceControlRepositoriesResult
Link copied to clipboard

List of actions for a business application system. Uses Azure REST API version 2024-04-01-preview. Other available API versions: 2024-10-01-preview, 2025-01-01-preview.

suspend fun listSystemActions(agentResourceName: String, resourceGroupName: String, systemResourceName: String, workspaceName: String): ListSystemActionsResult
Link copied to clipboard

Get whois information for a single domain name Uses Azure REST API version 2024-01-01-preview. Other available API versions: 2024-04-01-preview, 2024-10-01-preview, 2025-01-01-preview.

suspend fun listWhoisByDomain(domain: String? = null, enrichmentType: String, resourceGroupName: String, workspaceName: String): ListWhoisByDomainResult