External DocumentationTo learn more, visit the Microsoft Sentinel documentation.
Actions
List Incident Comments
Get all comments for a given incident.

Preview this Workflow on desktop
Was this page helpful?
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
| Parameter | Description |
|---|---|
| Incident ID | The ID of the incident, can be obtained by using the List Incidents action. |
| Resource Group Name | The name of the resource group. The name is case insensitive. |
| Return All Pages | Automatically fetch all resources, page by page. |
| Subscription ID | The ID of the target subscription. |
| Workspace Name | The name of the workspace. |
| Parameter | Description |
|---|---|
| Filter | Filter the results by inserting a query. Note: You can filter only based on properties attributes. Example: properties/message eq 'messageContent' |
| Order By | Sort the results by inserting a query. Example: properties/createdTimeUtc desc. |
| Skip Token | Specifies a starting point to show results from, this token is received in case that the previous request returned a partial result. |
| Top | Return Only the first n results. |
{
"results": [
{
"etag": "0300bf09-0000-0000-0000-5c37296e0000",
"id": "/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/providers/Microsoft.OperationalInsights/workspaces/myWorkspace/providers/Microsoft.SecurityInsights/incidents/73e01a99-5cd7-4139-a149-9f2736ff2ab5/comments/4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014",
"name": "4bb36b7b-26ff-4d1c-9cbe-0d8ab3da0014",
"properties": {
"author": {
"email": "john.doe@contoso.com",
"name": "john doe",
"objectId": "2046feea-040d-4a46-9e2b-91c2941bfa70",
"userPrincipalName": "john@contoso.com"
},
"createdTimeUtc": "2019-01-01T13:15:30Z",
"lastModifiedTimeUtc": "2019-01-01T13:15:30Z",
"message": "Some message"
},
"type": "Microsoft.SecurityInsights/incidents/comments"
}
]
}
Was this page helpful?