MicrosoftSecurityIncidentCreationAlertRuleCommonProperties Class

MicrosoftSecurityIncidentCreation rule common property bag.

All required parameters must be populated in order to send to Azure.

Inheritance
MicrosoftSecurityIncidentCreationAlertRuleCommonProperties

Constructor

MicrosoftSecurityIncidentCreationAlertRuleCommonProperties(*, product_filter: typing.Union[str, _ForwardRef('MicrosoftSecurityProductName')], display_names_filter: typing.Union[typing.List[str], NoneType] = None, display_names_exclude_filter: typing.Union[typing.List[str], NoneType] = None, severities_filter: typing.Union[typing.List[typing.Union[str, _ForwardRef('AlertSeverity')]], NoneType] = None, **kwargs)

Parameters

display_names_filter
list[str]
Required

the alerts' displayNames on which the cases will be generated.

display_names_exclude_filter
list[str]
Required

the alerts' displayNames on which the cases will not be generated.

product_filter
str or MicrosoftSecurityProductName
Required

Required. The alerts' productName on which the cases will be generated. Possible values include: "Microsoft Cloud App Security", "Azure Security Center", "Azure Advanced Threat Protection", "Azure Active Directory Identity Protection", "Azure Security Center for IoT".

severities_filter
list[str or AlertSeverity]
Required

the alerts' severities on which the cases will be generated.