Why Microsoft Sentinel alerts doesn't appear in graph api

Jérôme 90 Reputation points
2023-12-02T18:10:24.18+00:00

Hello,

I was wondering why when I query graph api to get Microsoft sentinel alerts, I can't see security alerts. is there some configuration to do ?

User's image

User's image

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 7,866 Reputation points MVP Volunteer Moderator
    2023-12-04T10:58:38.2066667+00:00

    Hello, the graph api gets data from Microsoft XDR (formally Defender 365) alerts, you need to use the Sentinel API for the ones you need.

    https://learn.microsoft.com/en-us/graph/api/resources/security-alert?view=graph-rest-1.0

    This resource corresponds to the latest generation of alerts in the Microsoft Graph security API, representing potential security issues within a customer's tenant that Microsoft 365 Defender, or a security provider integrated with Microsoft 365 Defender, has identified.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.