Get all watchlists.

External Documentation

To learn more, visit the Microsoft Sentinel documentation.

Basic Parameters

ParameterDescription
Resource Group NameThe name of the resource group. The name is case insensitive.
Subscription IDThe ID of the target subscription.
Workspace NameThe name of the workspace.

Advanced Parameters

ParameterDescription
Skip TokenSpecifies a starting point to show results from, this token is received in case that the previous request returned a partial result.

Example Output

{
	"value": [
		{
			"id": "/subscriptions/d0cfe6b2-9ac0-4464-9919-dccaee2e48c0/resourceGroups/myRg/providers/Microsoft.OperationalIinsights/workspaces/myWorkspace/providers/Microsoft.SecurityInsights/watchlists/highValueAsset",
			"name": "highValueAsset",
			"type": "Microsoft.SecurityInsights/Watchlists",
			"etag": "\"0300bf09-0000-0000-0000-5c37296e0000\"",
			"properties": {
				"watchlistId": "76d5a51f-ba1f-4038-9d22-59fda38dc017",
				"displayName": "High Value Assets Watchlist",
				"provider": "Microsoft",
				"source": "Local file",
				"created": "2020-09-28T00:26:54.7746089+00:00",
				"updated": "2020-09-28T00:26:57+00:00",
				"createdBy": {
					"objectId": "2046feea-040d-4a46-9e2b-91c2941bfa70",
					"email": "john@contoso.com",
					"name": "john doe"
				},
				"updatedBy": {
					"objectId": "2046feea-040d-4a46-9e2b-91c2941bfa70",
					"email": "john@contoso.com",
					"name": "john doe"
				},
				"description": "Watchlist from CSV content",
				"watchlistType": "watchlist",
				"watchlistAlias": "highValueAsset",
				"itemsSearchKey": "header1",
				"isDeleted": false,
				"labels": [
					"Tag1",
					"Tag2"
				],
				"defaultDuration": "P1279DT12H30M5S",
				"tenantId": "f686d426-8d16-42db-81b7-ab578e110ccd"
			}
		}
	]
}

Workflow Library Example

List Watchlists with Microsoft Sentinel and Send Results Via Email

Preview this Workflow on desktop