Edit

mailClusterEntityMapping resource type

Namespace: microsoft.graph.security

Important

APIs under the /beta version in Microsoft Graph are subject to change. Use of these APIs in production applications is not supported. To determine whether an API is available in v1.0, use the Version selector.

Represents a mapping from columns in a custom detection rule query result to a mail cluster entity that is attached to the resulting alert.

Base type: entityMapping.

Properties

Property Type Description
queryColumn String Name of the detection query column that maps to the query of the alert entity.
sourceColumn String Name of the detection query column that maps to the source of the alert entity.

Relationships

None.

JSON representation

The following JSON representation shows the resource type.

{
  "@odata.type": "#microsoft.graph.security.mailClusterEntityMapping",
  "queryColumn": "String",
  "sourceColumn": "String"
}