Skip to main content

actions

Creates, updates, deletes, gets or lists an actions resource.

Overview

Nameactions
TypeResource
Idazure.sentinel.actions

Fields

The following fields are returned by SELECT queries:

OK, Operation successfully completed

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}
namestringThe name of the resource
etagstringEtag of the action.
propertiesobjectAction properties for get request
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectsubscriptionId, resourceGroupName, workspaceName, ruleId, actionIdGets the action of alert rule.
list_by_alert_ruleselectsubscriptionId, resourceGroupName, workspaceName, ruleIdGets all actions of alert rule.
create_or_updateinsertsubscriptionId, resourceGroupName, workspaceName, ruleId, actionIdCreates or updates the action of alert rule.
deletedeletesubscriptionId, resourceGroupName, workspaceName, ruleId, actionIdDelete the action of alert rule.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
actionIdstringAction ID
resourceGroupNamestringThe name of the resource group. The name is case insensitive.
ruleIdstringAlert rule ID
subscriptionIdstringThe ID of the target subscription.
workspaceNamestringThe name of the workspace.

SELECT examples

Gets the action of alert rule.

SELECT
id,
name,
etag,
properties,
systemData,
type
FROM azure.sentinel.actions
WHERE subscriptionId = '{{ subscriptionId }}' -- required
AND resourceGroupName = '{{ resourceGroupName }}' -- required
AND workspaceName = '{{ workspaceName }}' -- required
AND ruleId = '{{ ruleId }}' -- required
AND actionId = '{{ actionId }}' -- required
;

INSERT examples

Creates or updates the action of alert rule.

INSERT INTO azure.sentinel.actions (
data__etag,
data__properties,
subscriptionId,
resourceGroupName,
workspaceName,
ruleId,
actionId
)
SELECT
'{{ etag }}',
'{{ properties }}',
'{{ subscriptionId }}',
'{{ resourceGroupName }}',
'{{ workspaceName }}',
'{{ ruleId }}',
'{{ actionId }}'
RETURNING
id,
name,
etag,
properties,
systemData,
type
;

DELETE examples

Delete the action of alert rule.

DELETE FROM azure.sentinel.actions
WHERE subscriptionId = '{{ subscriptionId }}' --required
AND resourceGroupName = '{{ resourceGroupName }}' --required
AND workspaceName = '{{ workspaceName }}' --required
AND ruleId = '{{ ruleId }}' --required
AND actionId = '{{ actionId }}' --required
;