Skip to main content

vw_incidents

Creates, updates, deletes, gets or lists a vw_incidents resource.

Overview

Namevw_incidents
TypeView
Idazure.sentinel.vw_incidents

Fields

See the SQL Definition (view DDL) for fields returned by this view.

SQL Definition

SELECT
etag as etag,
JSON_EXTRACT(properties, '$.additionalData') as "additional_data",
JSON_EXTRACT(properties, '$.classification') as "classification",
JSON_EXTRACT(properties, '$.classificationComment') as "classification_comment",
JSON_EXTRACT(properties, '$.classificationReason') as "classification_reason",
JSON_EXTRACT(properties, '$.createdTimeUtc') as "created_time_utc",
JSON_EXTRACT(properties, '$.description') as "description",
JSON_EXTRACT(properties, '$.firstActivityTimeUtc') as "first_activity_time_utc",
JSON_EXTRACT(properties, '$.incidentUrl') as "incident_url",
JSON_EXTRACT(properties, '$.providerName') as "provider_name",
JSON_EXTRACT(properties, '$.providerIncidentId') as "provider_incident_id",
JSON_EXTRACT(properties, '$.incidentNumber') as "incident_number",
JSON_EXTRACT(properties, '$.labels') as "labels",
JSON_EXTRACT(properties, '$.lastActivityTimeUtc') as "last_activity_time_utc",
JSON_EXTRACT(properties, '$.lastModifiedTimeUtc') as "last_modified_time_utc",
JSON_EXTRACT(properties, '$.owner') as "owner",
JSON_EXTRACT(properties, '$.relatedAnalyticRuleIds') as "related_analytic_rule_ids",
JSON_EXTRACT(properties, '$.severity') as "severity",
JSON_EXTRACT(properties, '$.status') as "status",
JSON_EXTRACT(properties, '$.title') as "title",
subscriptionId,
resourceGroupName,
workspaceName,
incidentId
FROM azure.sentinel.incidents
WHERE subscriptionId = 'replace-me' AND resourceGroupName = 'replace-me' AND workspaceName = 'replace-me';