Actions
Create Or Update Bookmark
Create or update a bookmark.
External Documentation
To learn more, visit the Microsoft Sentinel documentation.
Basic Parameters
Parameter | Description |
---|---|
Bookmark ID | Bookmark ID to upsert. If doesn’t exist, creates the bookmark with the given ID and properties (valid uuid). Otherwise, updates it. |
Display Name | The display name of the bookmark. |
Query | The query of the bookmark. |
Resource Group Name | The name of the resource group. The name is case insensitive. |
Subscription ID | The ID of the target subscription. |
Workspace Name | The name of the workspace. |
Advanced Parameters
Parameter | Description |
---|---|
Etag | The Etag of the azure resource. |
Event Time | The bookmark event time. |
Incident ID | The ID of the incident. |
Incident Info | Select to fill incident Info that describes an incident that relates to bookmark. |
Incident Relation Name | The relation name of the incident. |
Incident Severity | The severity of the incident. |
Incident Title | The title of the incident. |
Labels | A comma-separated list of labels that are relevant to this bookmark. |
Notes | The notes for the bookmark. |
Query End Time | The end time of the query. |
Query Result | The query result for the bookmark. |
Query Start time | The start time of the query. |
Example Output
Workflow Library Example
Create or Update Bookmark with Microsoft Sentinel and Send Results Via Email
Preview this Workflow on desktop
Was this page helpful?