Skip to main content

threat_intelligence_indicator

Creates, updates, deletes, gets or lists a threat_intelligence_indicator resource.

Overview

Namethreat_intelligence_indicator
TypeResource
Idazure.security_insight.threat_intelligence_indicator

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}.
namestringThe name of the resource.
etagstringEtag of the azure resource.
kindstringMetadata used by portal/tooling/etc to render different UX experiences for resources of the same type; e.g. ApiApps are a kind of Microsoft.Web/sites type. If supported, the resource provider must validate and persist this value. Required. "indicator"
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts".

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectresource_group_name, workspace_name, name, subscription_idView a threat intelligence indicator by name.
query_indicatorsselectresource_group_name, workspace_name, subscription_idQuery threat intelligence indicators as per filtering criteria.
createinsertresource_group_name, workspace_name, name, subscription_id, kindUpdate a threat Intelligence indicator.
deletedeleteresource_group_name, workspace_name, name, subscription_idDelete a threat intelligence indicator.
append_tagsexecresource_group_name, workspace_name, name, subscription_idAppend tags to a threat intelligence indicator.
replace_tagsexecresource_group_name, workspace_name, name, subscription_id, kindReplace tags added to a threat intelligence indicator.
create_indicatorexecresource_group_name, workspace_name, subscription_id, kindCreate a new threat intelligence indicator.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
namestringThreat intelligence indicator name field. Required.
resource_group_namestringThe name of the resource group. The name is case insensitive. Required.
subscription_idstring
workspace_namestringThe name of the monitor workspace. Required.

SELECT examples

View a threat intelligence indicator by name.

SELECT
id,
name,
etag,
kind,
systemData,
type
FROM azure.security_insight.threat_intelligence_indicator
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND workspace_name = '{{ workspace_name }}' -- required
AND name = '{{ name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;

INSERT examples

Update a threat Intelligence indicator.

INSERT INTO azure.security_insight.threat_intelligence_indicator (
kind,
etag,
properties,
resource_group_name,
workspace_name,
name,
subscription_id
)
SELECT
'{{ kind }}' /* required */,
'{{ etag }}',
'{{ properties }}',
'{{ resource_group_name }}',
'{{ workspace_name }}',
'{{ name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
etag,
kind,
systemData,
type
;

DELETE examples

Delete a threat intelligence indicator.

DELETE FROM azure.security_insight.threat_intelligence_indicator
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND workspace_name = '{{ workspace_name }}' --required
AND name = '{{ name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;

Lifecycle Methods

Append tags to a threat intelligence indicator.

EXEC azure.security_insight.threat_intelligence_indicator.append_tags 
@resource_group_name='{{ resource_group_name }}' --required,
@workspace_name='{{ workspace_name }}' --required,
@name='{{ name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"threatIntelligenceTags": "{{ threatIntelligenceTags }}"
}'
;