External DocumentationTo learn more, visit the Microsoft Sentinel documentation.
Basic Parameters
| Parameter | Description |
|---|---|
| Pattern | The pattern of the indicator. Example: [url:value = 'https://www.contoso.com'].Note: the pattern must be unique. |
| Pattern Type | The pattern type of the indicator. Example: url. |
| Resource Group Name | The name of the resource group. The name is case insensitive. |
| Source | The source of the indicator. |
| Subscription ID | The ID of the target subscription. |
| Workspace Name | The name of the workspace. |
Advanced Parameters
| Parameter | Description |
|---|---|
| Confidence | The confidence of the indicator. |
| Defanged | Is the indicator defanged. |
| Description | The description of the indicator. |
| Display Name | The display name of the indicator. |
| Etag | The Etag of the azure resource. |
| Extensions | Extensions map. |
| External ID | The external ID of the indicator. |
| External Last Updated Time UTC | External last updated time in UTC. |
| External References | A JSON list of references objects. Example: |
| Granular Markings | A JSON list of granular markings objects. Example: |
| Indicator Tags | A comma-separated list of indicator tags. |
| Indicator Types | A comma-separated list of indicator types. |
| Kill Chain Phases | A JSON list of kill chain phases objects. Example: |
| Labels | A comma-Separated list of labels. |
| Language | The language of the indicator. |
| Parsed Pattern | List of parsed patterns. Example: |
| Pattern Version | The pattern version of the indicator. |
| Threat Types | A comma-separated list of threat types. |
| Valid From | Valid from. |
| Valid Until | Valid until. |