Skip to main content

hunt_comments

Creates, updates, deletes, gets or lists a hunt_comments resource.

Overview

Namehunt_comments
TypeResource
Idazure.security_insight.hunt_comments

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}.
namestringThe name of the resource.
etagstringEtag of the azure resource.
messagestringThe message for the comment. Required.
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts".

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectresource_group_name, workspace_name, hunt_id, hunt_comment_id, subscription_idGets a hunt comment.
listselectresource_group_name, workspace_name, hunt_id, subscription_id$filter, $orderby, $top, $skipTokenGets all hunt comments.
create_or_updateinsertresource_group_name, workspace_name, hunt_id, hunt_comment_id, subscription_idCreates or updates a hunt relation.
create_or_updatereplaceresource_group_name, workspace_name, hunt_id, hunt_comment_id, subscription_idCreates or updates a hunt relation.
deletedeleteresource_group_name, workspace_name, hunt_id, hunt_comment_id, subscription_idDelete a hunt comment.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
hunt_comment_idstringThe hunt comment id (GUID). Required.
hunt_idstringThe hunt id (GUID). Required.
resource_group_namestringThe name of the resource group. The name is case insensitive. Required.
subscription_idstring
workspace_namestringThe name of the workspace. Required.
$filterstringFilters the results, based on a Boolean condition. Optional. Default value is None.
$orderbystringSorts the results. Optional. Default value is None.
$skipTokenstringSkiptoken is only used if a previous operation returned a partial result. If a previous response contains a nextLink element, the value of the nextLink element will include a skiptoken parameter that specifies a starting point to use for subsequent calls. Optional. Default value is None.
$topintegerReturns only the first n results. Optional. Default value is None.

SELECT examples

Gets a hunt comment.

SELECT
id,
name,
etag,
message,
systemData,
type
FROM azure.security_insight.hunt_comments
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND workspace_name = '{{ workspace_name }}' -- required
AND hunt_id = '{{ hunt_id }}' -- required
AND hunt_comment_id = '{{ hunt_comment_id }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;

INSERT examples

Creates or updates a hunt relation.

INSERT INTO azure.security_insight.hunt_comments (
properties,
etag,
resource_group_name,
workspace_name,
hunt_id,
hunt_comment_id,
subscription_id
)
SELECT
'{{ properties }}',
'{{ etag }}',
'{{ resource_group_name }}',
'{{ workspace_name }}',
'{{ hunt_id }}',
'{{ hunt_comment_id }}',
'{{ subscription_id }}'
RETURNING
id,
name,
etag,
properties,
systemData,
type
;

REPLACE examples

Creates or updates a hunt relation.

REPLACE azure.security_insight.hunt_comments
SET
properties = '{{ properties }}',
etag = '{{ etag }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND hunt_id = '{{ hunt_id }}' --required
AND hunt_comment_id = '{{ hunt_comment_id }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
etag,
properties,
systemData,
type;

DELETE examples

Delete a hunt comment.

DELETE FROM azure.security_insight.hunt_comments
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND hunt_id = '{{ hunt_id }}' --required
AND hunt_comment_id = '{{ hunt_comment_id }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;