MS 365 Defender: Alert > event > "Inspect Records" via API

zr123 1 Reputation point
2022-04-04T20:31:06.893+00:00

MS 365 Defender: Alert > event > "Inspect Records" via API
On the MS 365 Console, I can see related events to an alert. As well, I can get an "Inspect Record" screen to see even more details.

How can I get to that event>Inspect Record information via the API / Hunting ?

It seems that the List alerts API would give me the information I need, but I can't seem to access it for any of the Microsoft 365 Defender alerts I tried. I can access it for other alerts. It is not compatible with MS 365 Defender?

The top URL says it is, the bottom one, doesn't mention it:
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/get-alerts?view=o365-worldwide

https://learn.microsoft.com/en-us/microsoft-365/security/defender/api-supported?view=o365-worldwide

Thanks

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,575 questions
0 comments No comments
{count} votes