What does the 'DefaultDuration' field mean in the Watchlist table

Sándor Tőkési 271 Reputation points
2023-11-05T16:20:55.99+00:00

When I create a watchlist via the API I have the option to configure this value. Also if I look up the Watchlist table in Sentinel I can see this DefaultDuration field.
All my watchlists (created via the GUI) have 1D 3H configured as DefaultDuration.

Does anybody know what this field mean? I looked up the Watchlist table documentation but it only says this is a default duration value inherited by the items. But it is not clear to me what this value actually affects and how my watchlist will act if I define a different value during creation. Any ideas?

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2023-11-06T08:10:48.21+00:00

    Hi, when I last asked Microsoft this was the answer (~16mths ago):

    Q: Do watchlists expire or remain forever?

    Watchlists - List - REST API (Azure Sentinel) | Microsoft Docs has a properties.defaultDuration (which seems to be 1day 3hrs) but what is it there for / actually do?

    Answer:

    This is a future capability, currently not active

    If this answer helps, please Accept.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.