Skip to main content
POST
List incidents across workspaces

Body

application/json

v2 request for listing incidents across multiple workspaces.

severities
null | enum<string>[]

Filter incidents to only the listed severities. Empty list returns all severities.

Available options:
Informational,
Low,
Medium,
High
statuses
null | enum<string>[]

Filter incidents to only the listed statuses. Empty list returns all statuses.

Available options:
Active,
New,
Closed,
OnHold,
WaitingOnCustomer
timeFilterSelection
object

Time window applied to the incident's creation time, or to its last-modified time when filterByLastModified is true. Defaults to the last 24 hours.

filterByLastModified
boolean

When true, timeFilterSelection bounds the incident's last-modified time instead of its creation time, and each page is ordered by last-modified time descending. Use this to synchronise updates into an external system: poll a short window that ends at the time of the call and receive every incident whose Microsoft Sentinel or Microsoft Defender XDR record changed in that window (alert grouped in, severity, status, owner, label, comment), including incidents created long before the window. An incident created inside the window but modified after its end is not in this window; it appears in the next one. In this mode each workspace's window is returned in full in one call unless it exceeds the server's page cap; if moreIncidentsAvailable is true, narrow the window rather than paging, because vendor continuations are positional and a concurrent edit can shift them. The timestamp is the vendor's (lastModifiedTimeUtc / lastUpdateDateTime), not lastActivityTime. Supported for Sentinel and DefenderXDR only: an empty sources list selects those two, and listing any other source together with this flag returns 400.

workspacePageTokens
null | object[]

Opaque pagination tokens echoed from the previous response's SourcePageTokens. Leave empty on the first call. See type-level remarks for the pagination protocol.

query
null | string

Free-text search applied across incident title/description fields. Empty matches all.

isFirstCall
boolean

true for the initial request; false when echoing List<WorkspaceSourcePageTokens> ListIncidentsAcrossWorkspacesRequest.WorkspacePageTokens back for subsequent pages. See type-level remarks for the pagination protocol.

sources
null | enum<string>[]

Filter incidents to only the listed sources (e.g. Sentinel, DefenderXDR, CrowdStrike). Empty list returns all sources the caller has access to.

Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne
assigneeIds
null | string[]

Filter incidents assigned to any of the listed ContraForce user IDs.

assigneeEmails
null | string[]

Filter incidents assigned to any of the listed user email addresses.

includeUnassigned
boolean

When true, include incidents that have no assignee alongside any matches from List<string> ListIncidentsAcrossWorkspacesRequest.AssigneeIds / List<string> ListIncidentsAcrossWorkspacesRequest.AssigneeEmails.

Response

OK

Standard v2 API response envelope for single-item responses.

data
object

Wraps the result of listing incidents for multiple workspaces in the multi-tenancy mode.

meta
object