Microsoft Sentinel Azure-Microsoft.SecurityInsights

operationNameDescriptionSampleRule
anyCatch-all for Azure-Microsoft.SecurityInsights rules that match the resource provider but no specific operation.NN
Microsoft.SecurityInsights/alertRules/actions/deleteDeletes the response actions of an alert ruleNN
Microsoft.SecurityInsights/alertRules/actions/writeUpdates the response actions of an alert ruleNN
Microsoft.SecurityInsights/alertRules/deleteDeletes alert rulesNN
Microsoft.SecurityInsights/alertRules/triggerRuleRun/actionTrigger on-demand rule run executionNN
Microsoft.SecurityInsights/alertRules/writeUpdates alert rulesYN
Microsoft.SecurityInsights/automationRules/deleteDeletes an automation ruleNN
Microsoft.SecurityInsights/automationRules/writeUpdates an automation ruleNN
Microsoft.SecurityInsights/Bookmarks/deleteDeletes bookmarksYN
Microsoft.SecurityInsights/Bookmarks/expand/actionGets related entities of an entity by a specific expansionNN
Microsoft.SecurityInsights/bookmarks/relations/deleteDeletes a bookmark relationNN
Microsoft.SecurityInsights/bookmarks/relations/writeUpdates a bookmark relationNN
Microsoft.SecurityInsights/Bookmarks/writeUpdates bookmarksYN
Microsoft.SecurityInsights/cases/comments/writeCreates the case commentsNN
Microsoft.SecurityInsights/cases/deleteDeletes a caseNN
Microsoft.SecurityInsights/cases/investigations/writeUpdates the metadata of a caseNN
Microsoft.SecurityInsights/cases/writeUpdates a caseNN
Microsoft.SecurityInsights/ConfidentialWatchlists/deleteDeletes Confidential WatchlistsNN
Microsoft.SecurityInsights/ConfidentialWatchlists/writeCreates Confidential WatchlistsNN
Microsoft.SecurityInsights/ContentPackages/deleteDelete Installed Content Packages.NN
Microsoft.SecurityInsights/ContentPackages/writeInstall Content Packages.NN
Microsoft.SecurityInsights/ContentTemplates/deleteDelete Installed Content Templates.NN
Microsoft.SecurityInsights/ContentTemplates/writeInstall Content Templates.NN
Microsoft.SecurityInsights/dataConnectors/deleteDeletes a data connectorNN
Microsoft.SecurityInsights/dataConnectors/writeUpdates a data connectorYN
Microsoft.SecurityInsights/dataConnectorsCheckRequirements/actionCheck user authorization and licenseNN
Microsoft.SecurityInsights/entities/getInsights/actionGets entity Insights for a specific rangeNN
Microsoft.SecurityInsights/entities/gettimeline/actionGets entity timeline for a specific rangeNN
Microsoft.SecurityInsights/entities/relations/deleteDeletes a relation between the entity and related resourcesNN
Microsoft.SecurityInsights/entities/relations/writeUpdates a relation between the entity and related resourcesNN
Microsoft.SecurityInsights/entities/runPlaybook/actionRun playbook on entityNN
Microsoft.SecurityInsights/ExportConnections/deleteDelete ExportConnectionsNN
Microsoft.SecurityInsights/ExportConnections/ExportJobs/deleteDelete ExportJobsNN
Microsoft.SecurityInsights/ExportConnections/ExportJobs/writewrite ExportJobsNN
Microsoft.SecurityInsights/ExportConnections/writewrite ExportConnectionsNN
Microsoft.SecurityInsights/fileimports/deleteDeletes a File ImportNN
Microsoft.SecurityInsights/fileimports/writeCreates or updates a File ImportNN
Microsoft.SecurityInsights/hunts/comments/deleteDeletes Hunt CommentsNN
Microsoft.SecurityInsights/hunts/comments/writeCreate Hunt CommentsNN
Microsoft.SecurityInsights/hunts/deleteDeletes HuntsNN
Microsoft.SecurityInsights/hunts/relations/deleteDeletes Hunt RelationsNN
Microsoft.SecurityInsights/hunts/relations/writeCreate Hunt RelationsNN
Microsoft.SecurityInsights/hunts/writeCreate HuntsNN
Microsoft.SecurityInsights/incidents/comments/deleteDeletes a comment on the incidentNN
Microsoft.SecurityInsights/incidents/comments/writeCreates a comment on the incidentNN
Microsoft.SecurityInsights/incidents/createTeam/actionCreates a Microsoft team to investigate the incident by sharing information and insights between participantsNN
Microsoft.SecurityInsights/incidents/deleteDeletes an incidentYN
Microsoft.SecurityInsights/incidents/relations/deleteDeletes a relation between the incident and related resourcesNN
Microsoft.SecurityInsights/incidents/relations/writeUpdates a relation between the incident and related resourcesNN
Microsoft.SecurityInsights/incidents/runPlaybook/actionRun playbook on incidentNN
Microsoft.SecurityInsights/incidents/tasks/deleteDeletes a task on the incidentNN
Microsoft.SecurityInsights/incidents/tasks/writeUpdates a task on the incidentNN
Microsoft.SecurityInsights/incidents/writeUpdates an incidentYN
Microsoft.SecurityInsights/Metadata/deleteDelete Metadata for Sentinel content.NN
Microsoft.SecurityInsights/Metadata/writeWrite Metadata for Sentinel content.NN
Microsoft.SecurityInsights/officeConsents/deleteDeletes consents from Microsoft OfficeNN
Microsoft.SecurityInsights/onboardingStates/deleteDeletes an onboarding stateNN
Microsoft.SecurityInsights/onboardingStates/writeUpdates an onboarding stateYN
Microsoft.SecurityInsights/register/actionRegisters the subscription to Azure SentinelNN
Microsoft.SecurityInsights/securityMLAnalyticsSettings/deleteDelete an analytics settingNN
Microsoft.SecurityInsights/securityMLAnalyticsSettings/writeUpdate the analytics settingsNN
Microsoft.SecurityInsights/settings/deleteDeletes settingNN
Microsoft.SecurityInsights/settings/writeUpdates settingsNN
Microsoft.SecurityInsights/SourceControls/deleteDelete SourceControlsNN
Microsoft.SecurityInsights/SourceControls/writewrite SourceControlsNN
Microsoft.SecurityInsights/threatintelligence/bulkactions/count/actionQuery Threat Intelligence STIX object countNN
Microsoft.SecurityInsights/threatintelligence/bulkactions/deleteDeletes a TI Bulk ActionNN
Microsoft.SecurityInsights/threatintelligence/bulkactions/query/actionQuery Threat Intelligence STIX objectsNN
Microsoft.SecurityInsights/threatintelligence/bulkactions/writeCreates or updates a TI Bulk ActionNN
Microsoft.SecurityInsights/threatintelligence/bulkDelete/actionBulk Delete Threat IntelligenceNN
Microsoft.SecurityInsights/threatintelligence/bulkTag/actionBulk Tags Threat IntelligenceNN
Microsoft.SecurityInsights/threatintelligence/createIndicator/actionCreate Threat Intelligence IndicatorNN
Microsoft.SecurityInsights/threatintelligence/deleteDeletes Threat IntelligenceNN
Microsoft.SecurityInsights/threatintelligence/indicators/appendTags/actionAppend tags to Threat Intelligence IndicatorNN
Microsoft.SecurityInsights/threatintelligence/indicators/bulkDelete/actionBulk Delete Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/indicators/bulkTag/actionBulk Tags Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/indicators/deleteDeletes Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/indicators/metrics/actionGet Threat Intelligence Indicator MetricsNN
Microsoft.SecurityInsights/threatintelligence/indicators/query/actionQuery Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/indicators/replaceTags/actionReplace Tags of Threat Intelligence IndicatorNN
Microsoft.SecurityInsights/threatintelligence/indicators/writeUpdates Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/ingestionrulelist/writeCreates or updates a set of TI Ingestion RulesNN
Microsoft.SecurityInsights/threatintelligence/metrics/actionCollect Threat Intelligence MetricsNN
Microsoft.SecurityInsights/threatintelligence/query/actionQuery Threat IntelligenceNN
Microsoft.SecurityInsights/threatintelligence/queryIndicators/actionQuery Threat Intelligence IndicatorsNN
Microsoft.SecurityInsights/threatintelligence/threatactors/deleteDeletes a TI Threat ActorNN
Microsoft.SecurityInsights/threatintelligence/threatactors/writeCreates or updates a TI Threat ActorNN
Microsoft.SecurityInsights/threatintelligence/writeUpdates Threat IntelligenceNN
Microsoft.SecurityInsights/unregister/actionUnregisters the subscription from Azure SentinelNN
Microsoft.SecurityInsights/Watchlists/deleteDeletes WatchlistsYN
Microsoft.SecurityInsights/Watchlists/writeCreate WatchlistsYN
Microsoft.SecurityInsights/WorkspaceManagerAssignments/deleteDeletes WorkspaceManager AssignmentsNN
Microsoft.SecurityInsights/workspaceManagerAssignments/jobs/deleteDeletes WorkspaceManagerAssignments jobsNN
Microsoft.SecurityInsights/workspaceManagerAssignments/jobs/writeCreates WorkspaceManagerAssignments jobsNN
Microsoft.SecurityInsights/WorkspaceManagerAssignments/writeCreates WorkspaceManager AssignmentsNN
Microsoft.SecurityInsights/WorkspaceManagerConfigurations/deleteDeletes WorkspaceManager ConfigurationsNN
Microsoft.SecurityInsights/WorkspaceManagerConfigurations/writeCreates WorkspaceManager ConfigurationsNN
Microsoft.SecurityInsights/WorkspaceManagerGroups/deleteDeletes WorkspaceManager GroupsNN
Microsoft.SecurityInsights/WorkspaceManagerGroups/writeCreates WorkspaceManager GroupsNN
Microsoft.SecurityInsights/WorkspaceManagerMembers/deleteDeletes WorkspaceManager MembersNN
Microsoft.SecurityInsights/WorkspaceManagerMembers/writeCreates WorkspaceManager MembersNN

any: Microsoft Sentinel (catch-all)

#
Namespace
Microsoft.SecurityInsights

Description

Catch-all for Azure-Microsoft.SecurityInsights rules that match the resource provider but no specific operation.

References #

Microsoft.SecurityInsights/alertRules/actions/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes the response actions of an alert rule

References #

Microsoft.SecurityInsights/alertRules/actions/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates the response actions of an alert rule

References #

Microsoft.SecurityInsights/alertRules/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes alert rules

References #

Microsoft.SecurityInsights/alertRules/triggerRuleRun/action

#
Namespace
Microsoft.SecurityInsights

Description

Trigger on-demand rule run execution

References #

Microsoft.SecurityInsights/alertRules/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates alert rules

Example Resource Log Record #

{
  "TenantId": "7c759f10-811c-4db8-ad6d-f07d8ae3f8ea",
  "SourceSystem": "Azure",
  "CallerIpAddress": "37.142.150.162",
  "CategoryValue": "Administrative",
  "CorrelationId": "22c5c3ad-e049-48b1-be62-19076302c6e4",
  "Authorization": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/sentinelyanivsh/providers/Microsoft.OperationalInsights/workspaces/centricdemo/providers/Microsoft.SecurityInsights/alertRules/017c0f30-87ea-4ab0-802a-51def37b0721",
    "action": "Microsoft.SecurityInsights/alertRules/write",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/sentinelyanivsh/providers/Microsoft.OperationalInsights/workspaces/centricdemo/providers/Microsoft.SecurityInsights/alertRules/017c0f30-87ea-4ab0-802a-51def37b0721",
    "action": "Microsoft.SecurityInsights/alertRules/write",
    "evidence": {
      "role": "Contributor",
      "roleAssignmentScope": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918",
      "roleAssignmentId": "9ddc3bf8125f4918ad9f9dd31a0ae60f",
      "roleDefinitionId": "b24988ac618042a0ab8820f7382dd24c",
      "principalId": "9b117c67170e4aed9702658b3fddc889",
      "principalType": "User"
    }
  },
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619619948",
    "nbf": "1619619948",
    "exp": "1619623848",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "thrQim_Tb0K8ZxSi9VWAAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/2ad3fc79-1859-42fa-9011-6f8df2251b22/",
    "iat": "1619619948",
    "nbf": "1619619948",
    "exp": "1619623848",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "aio": "ATQAy/8TAAAARk47FymlkYjF8aD5qw9R6mifAuz/IGhhTRBHWebW9HOR9MgLKM4YcDn72FFfKrZz",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd",
    "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c",
    "appidacr": "2",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "Vance",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Adele",
    "groups": "b8ebf801-537d-4ef0-9353-545d8b161a4c,4dee65d3-7474-4a57-b550-19b1435e6fdc,dc8c1d8a-5cbe-4db7-a252-ed6e77a9bac6,72d050bc-1235-43d2-be81-4029fbfbd6c7,0d569539-ca8f-4e1b-bfbd-35e57b0d4bf1,8041dfc5-efef-4035-8241-74179adf4b9f",
    "ipaddr": "37.142.150.162",
    "name": "Adele Vance",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "9b117c67-170e-4aed-9702-658b3fddc889",
    "puid": "10032000C757D25F",
    "rh": "0.AVIAefzTKlkY-kKQEW-N8iUbIoNAS8SwO8FJtH2XTlPL3zxSAJg.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "ZkJagYHGZD8_R8qCe2VRG3nD8dGJehXAuGi58QDeOtM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "2ad3fc79-1859-42fa-9011-6f8df2251b22",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "AdeleV@M365x816222.OnMicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "AdeleV@M365x816222.OnMicrosoft.com",
    "uti": "thrQim_Tb0K8ZxSi9VWAAQ",
    "ver": "1.0",
    "xms_tcdt": "1591748537"
  },
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/ALERTRULES/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": null,
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/sentinelyanivsh/providers/Microsoft.OperationalInsights/workspaces/centricdemo/providers/Microsoft.SecurityInsights/alertRules/017c0f30-87ea-4ab0-802a-51def37b0721",
    "message": "Microsoft.SecurityInsights/alertRules/write",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "ce96bc52-0093-49aa-af81-f1d22a72e6f0",
    "eventSubmissionTimestamp": "2021-04-28T14:35:00.6739282Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "centricdemo/microsoft.securityinsights/017c0f30-87ea-4ab0-802a-51def37b0721",
    "resourceGroup": "SENTINELYANIVSH",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "8F153238-E602-427E-A7C0-3043FBE50918",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "statusCode": "Created",
    "serviceRequestId": null,
    "eventCategory": "Administrative",
    "entity": "/subscriptions/8f153238-e602-427e-a7c0-3043fbe50918/resourceGroups/sentinelyanivsh/providers/Microsoft.OperationalInsights/workspaces/centricdemo/providers/Microsoft.SecurityInsights/alertRules/017c0f30-87ea-4ab0-802a-51def37b0721",
    "message": "Microsoft.SecurityInsights/alertRules/write",
    "hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
    "caller": "AdeleV@M365x816222.OnMicrosoft.com",
    "eventDataId": "ce96bc52-0093-49aa-af81-f1d22a72e6f0",
    "eventSubmissionTimestamp": "2021-04-28T14:35:00.6739282Z",
    "httpRequest": {
      "clientIpAddress": "37.142.150.162"
    },
    "resource": "centricdemo/microsoft.securityinsights/017c0f30-87ea-4ab0-802a-51def37b0721",
    "resourceGroup": "SENTINELYANIVSH",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Caller": "AdeleV@M365x816222.OnMicrosoft.com",
  "EventDataId": "ce96bc52-0093-49aa-af81-f1d22a72e6f0",
  "EventSubmissionTimestamp": "4/28/2021, 2:35:00.673 PM",
  "HTTPRequest": {
    "clientIpAddress": "37.142.150.162"
  },
  "ResourceGroup": "SENTINELYANIVSH",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Hierarchy": "2ad3fc79-1859-42fa-9011-6f8df2251b22/CONTOSO-MG/8f153238-e602-427e-a7c0-3043fbe50918",
  "TimeGenerated": "4/28/2021, 2:35:00.673 PM",
  "SubscriptionId": "8f153238-e602-427e-a7c0-3043fbe50918",
  "Type": "AzureActivity"
}

References #

Microsoft.SecurityInsights/automationRules/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes an automation rule

References #

Microsoft.SecurityInsights/automationRules/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates an automation rule

References #

Microsoft.SecurityInsights/Bookmarks/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes bookmarks

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "action": "Microsoft.SecurityInsights/bookmarks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "action": "Microsoft.SecurityInsights/bookmarks/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "e2ec9ef9-4875-4746-83ca-913f66eb7bee",
  "EventDataId": "ea7ded92-7d7c-77d2-7af7-070c3d232efd",
  "EventSubmissionTimestamp": "2026-07-04T15:08:08.7740487Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/BOOKMARKS/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "message": "Microsoft.SecurityInsights/bookmarks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "ea7ded92-7d7c-77d2-7af7-070c3d232efd",
    "eventSubmissionTimestamp": "2026-07-04T15:08:08.7740487Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/806310c7-579b-5846-976e-b5f2855fdebe",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "message": "Microsoft.SecurityInsights/bookmarks/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "ea7ded92-7d7c-77d2-7af7-070c3d232efd",
    "eventSubmissionTimestamp": "2026-07-04T15:08:08.7740487Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/806310c7-579b-5846-976e-b5f2855fdebe",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/Bookmarks/expand/action

#
Namespace
Microsoft.SecurityInsights

Description

Gets related entities of an entity by a specific expansion

References #

Microsoft.SecurityInsights/bookmarks/relations/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a bookmark relation

References #

Microsoft.SecurityInsights/bookmarks/relations/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a bookmark relation

References #

Microsoft.SecurityInsights/Bookmarks/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates bookmarks

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "action": "Microsoft.SecurityInsights/bookmarks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "action": "Microsoft.SecurityInsights/bookmarks/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "e64b017b-e7ee-4644-afcc-e9f28871705b",
  "EventDataId": "92d50b70-6ad3-f9e1-3b80-535c74e668a8",
  "EventSubmissionTimestamp": "2026-07-04T15:08:07.4985887Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/BOOKMARKS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "message": "Microsoft.SecurityInsights/bookmarks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "92d50b70-6ad3-f9e1-3b80-535c74e668a8",
    "eventSubmissionTimestamp": "2026-07-04T15:08:07.4985887Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/806310c7-579b-5846-976e-b5f2855fdebe",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/bookmarks/806310c7-579b-5846-976e-b5f2855fdebe",
    "message": "Microsoft.SecurityInsights/bookmarks/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "92d50b70-6ad3-f9e1-3b80-535c74e668a8",
    "eventSubmissionTimestamp": "2026-07-04T15:08:07.4985887Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/806310c7-579b-5846-976e-b5f2855fdebe",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/cases/comments/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates the case comments

References #

Microsoft.SecurityInsights/cases/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a case

References #

Microsoft.SecurityInsights/cases/investigations/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates the metadata of a case

References #

Microsoft.SecurityInsights/cases/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a case

References #

Microsoft.SecurityInsights/ConfidentialWatchlists/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Confidential Watchlists

References #

Microsoft.SecurityInsights/ConfidentialWatchlists/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates Confidential Watchlists

References #

Microsoft.SecurityInsights/ContentPackages/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete Installed Content Packages.

References #

Microsoft.SecurityInsights/ContentPackages/write

#
Namespace
Microsoft.SecurityInsights

Description

Install Content Packages.

References #

Microsoft.SecurityInsights/ContentTemplates/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete Installed Content Templates.

References #

Microsoft.SecurityInsights/ContentTemplates/write

#
Namespace
Microsoft.SecurityInsights

Description

Install Content Templates.

References #

Microsoft.SecurityInsights/dataConnectors/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a data connector

References #

Microsoft.SecurityInsights/dataConnectors/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a data connector

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/dataConnectors/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "action": "Microsoft.SecurityInsights/dataConnectors/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/dataConnectors/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "action": "Microsoft.SecurityInsights/dataConnectors/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782958076",
    "nbf": "1782958076",
    "exp": "1782963611",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAfdZqVkcUnr0OgyMRfsDFBDcFN81INZHA2vyqbXePYZ9AHYb6GhAqrRZSI60vYmXjFGMv3fk7Ur61ZaHhjkYU8XiHOVQqdhfrwBKn4fZ+CV4KWm/bM80N9/3yO5AmI2MvHMAIs6kNwFywD4AaocVMWQ==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "GkVuS8OIoka2wCulz2hVAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "Ua3bOV9MyMmqdL1QWIunXnkyyAaZFzhrUwd2TyCahoIBdXNzb3V0aC1kc21z",
    "xms_idrel": "10 1",
    "xms_sub_fct": "3 12",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1782958076",
    "nbf": "1782958076",
    "exp": "1782963611",
    "aio": "AXQAi/8cAAAAfdZqVkcUnr0OgyMRfsDFBDcFN81INZHA2vyqbXePYZ9AHYb6GhAqrRZSI60vYmXjFGMv3fk7Ur61ZaHhjkYU8XiHOVQqdhfrwBKn4fZ+CV4KWm/bM80N9/3yO5AmI2MvHMAIs6kNwFywD4AaocVMWQ==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "GkVuS8OIoka2wCulz2hVAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "Ua3bOV9MyMmqdL1QWIunXnkyyAaZFzhrUwd2TyCahoIBdXNzb3V0aC1kc21z",
    "xms_idrel": "10 1",
    "xms_sub_fct": "3 12",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "09101997-5852-44d8-9b9d-f3bd98974eb2",
  "EventDataId": "bfc650b1-ba9f-6d95-51fa-e4ac9165af62",
  "EventSubmissionTimestamp": "2026-07-02T02:16:17.5302167Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/DATACONNECTORS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/dataConnectors/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "message": "Microsoft.SecurityInsights/dataConnectors/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bfc650b1-ba9f-6d95-51fa-e4ac9165af62",
    "eventSubmissionTimestamp": "2026-07-02T02:16:17.5302167Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/dataConnectors/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "message": "Microsoft.SecurityInsights/dataConnectors/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "bfc650b1-ba9f-6d95-51fa-e4ac9165af62",
    "eventSubmissionTimestamp": "2026-07-02T02:16:17.5302167Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/2189e518-cc36-4209-b130-0396dc5ca6ce",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/dataConnectorsCheckRequirements/action

#
Namespace
Microsoft.SecurityInsights

Description

Check user authorization and license

References #

Microsoft.SecurityInsights/entities/getInsights/action

#
Namespace
Microsoft.SecurityInsights

Description

Gets entity Insights for a specific range

References #

Microsoft.SecurityInsights/entities/gettimeline/action

#
Namespace
Microsoft.SecurityInsights

Description

Gets entity timeline for a specific range

References #

Microsoft.SecurityInsights/entities/relations/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a relation between the entity and related resources

References #

Microsoft.SecurityInsights/entities/relations/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a relation between the entity and related resources

References #

Microsoft.SecurityInsights/entities/runPlaybook/action

#
Namespace
Microsoft.SecurityInsights

Description

Run playbook on entity

References #

Microsoft.SecurityInsights/ExportConnections/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete ExportConnections

References #

Microsoft.SecurityInsights/ExportConnections/ExportJobs/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete ExportJobs

References #

Microsoft.SecurityInsights/ExportConnections/ExportJobs/write

#
Namespace
Microsoft.SecurityInsights

Description

write ExportJobs

References #

Microsoft.SecurityInsights/ExportConnections/write

#
Namespace
Microsoft.SecurityInsights

Description

write ExportConnections

References #

Microsoft.SecurityInsights/fileimports/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a File Import

References #

Microsoft.SecurityInsights/fileimports/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates or updates a File Import

References #

Microsoft.SecurityInsights/hunts/comments/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Hunt Comments

References #

Microsoft.SecurityInsights/hunts/comments/write

#
Namespace
Microsoft.SecurityInsights

Description

Create Hunt Comments

References #

Microsoft.SecurityInsights/hunts/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Hunts

References #

Microsoft.SecurityInsights/hunts/relations/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Hunt Relations

References #

Microsoft.SecurityInsights/hunts/relations/write

#
Namespace
Microsoft.SecurityInsights

Description

Create Hunt Relations

References #

Microsoft.SecurityInsights/hunts/write

#
Namespace
Microsoft.SecurityInsights

Description

Create Hunts

References #

Microsoft.SecurityInsights/incidents/comments/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a comment on the incident

References #

Microsoft.SecurityInsights/incidents/comments/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates a comment on the incident

References #

Microsoft.SecurityInsights/incidents/createTeam/action

#
Namespace
Microsoft.SecurityInsights

Description

Creates a Microsoft team to investigate the incident by sharing information and insights between participants

References #

Microsoft.SecurityInsights/incidents/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes an incident

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "action": "Microsoft.SecurityInsights/incidents/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "action": "Microsoft.SecurityInsights/incidents/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "bde88d90-012d-4b24-8cbb-9ea41a029780",
  "EventDataId": "c7ba0fd1-025b-94ca-d54d-a01775a1099f",
  "EventSubmissionTimestamp": "2026-07-04T15:08:11.3172354Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/INCIDENTS/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "message": "Microsoft.SecurityInsights/incidents/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c7ba0fd1-025b-94ca-d54d-a01775a1099f",
    "eventSubmissionTimestamp": "2026-07-04T15:08:11.3172354Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "message": "Microsoft.SecurityInsights/incidents/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "c7ba0fd1-025b-94ca-d54d-a01775a1099f",
    "eventSubmissionTimestamp": "2026-07-04T15:08:11.3172354Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/incidents/relations/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a relation between the incident and related resources

References #

Microsoft.SecurityInsights/incidents/relations/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a relation between the incident and related resources

References #

Microsoft.SecurityInsights/incidents/runPlaybook/action

#
Namespace
Microsoft.SecurityInsights

Description

Run playbook on incident

References #

Microsoft.SecurityInsights/incidents/tasks/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a task on the incident

References #

Microsoft.SecurityInsights/incidents/tasks/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates a task on the incident

References #

Microsoft.SecurityInsights/incidents/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates an incident

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "Created",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "action": "Microsoft.SecurityInsights/incidents/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "action": "Microsoft.SecurityInsights/incidents/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "3eddfd7e-9163-4468-864f-c10ccb002afd",
  "EventDataId": "9bab8aa9-97dc-e95d-ca38-e41d1312d7ec",
  "EventSubmissionTimestamp": "2026-07-04T15:08:10.06649Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/INCIDENTS/WRITE",
  "Properties": {
    "statusCode": "Created",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "message": "Microsoft.SecurityInsights/incidents/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bab8aa9-97dc-e95d-ca38-e41d1312d7ec",
    "eventSubmissionTimestamp": "2026-07-04T15:08:10.06649Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "Created"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/incidents/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "message": "Microsoft.SecurityInsights/incidents/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "9bab8aa9-97dc-e95d-ca38-e41d1312d7ec",
    "eventSubmissionTimestamp": "2026-07-04T15:08:10.0664900Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/1fb0e087-5417-5614-8dab-f4f111e7eaaa",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "Created",
    "serviceRequestId": "",
    "activitySubstatusValue": "Created"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/Metadata/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete Metadata for Sentinel content.

References #

Microsoft.SecurityInsights/Metadata/write

#
Namespace
Microsoft.SecurityInsights

Description

Write Metadata for Sentinel content.

References #

Microsoft.SecurityInsights/officeConsents/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes consents from Microsoft Office

References #

Microsoft.SecurityInsights/onboardingStates/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes an onboarding state

References #

Microsoft.SecurityInsights/onboardingStates/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates an onboarding state

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/onboardingStates/default",
    "action": "Microsoft.SecurityInsights/onboardingStates/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/onboardingStates/default",
    "action": "Microsoft.SecurityInsights/onboardingStates/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783015763",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282",
    "correlationid": "a3ccca4c-d9d1-42e5-b504-b87c87e15a29"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783008141",
    "nbf": "1783008141",
    "exp": "1783015763",
    "aio": "AXQAi/8cAAAA/aDiVwsbwk18GnYlWFKcBZb5UnBAQGny1deUBCpk1wvoaHC8c2/faUwhIvEz+jwqEuUDCPj+rYXDoVSb1JJf9R46RD6wFcSirzyy+XCnUul9/w/A8ltH8m9fyV37DTPYPQgVJ1Dy4Ln3oeVqMfWc/Q==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "joig862JV0W_vEH8aP97AA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "3 5",
    "xms_ftd": "MYmqIV5FdoWQjoUa-o05_qMtUfBKgIRMCe4pE3a1yrwBdXNub3J0aC1kc21z",
    "xms_idrel": "1 6",
    "xms_sub_fct": "3 8",
    "xms_tcdt": "1768616282",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "correlationid": "a3ccca4c-d9d1-42e5-b504-b87c87e15a29"
  },
  "CorrelationId": "a3ccca4c-d9d1-42e5-b504-b87c87e15a29",
  "EventDataId": "e8c1770a-aacc-9124-6d50-abe842c48467",
  "EventSubmissionTimestamp": "2026-07-02T16:09:23.9378579Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/ONBOARDINGSTATES/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/onboardingStates/default",
    "message": "Microsoft.SecurityInsights/onboardingStates/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e8c1770a-aacc-9124-6d50-abe842c48467",
    "eventSubmissionTimestamp": "2026-07-02T16:09:23.9378579Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/default",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/onboardingStates/default",
    "message": "Microsoft.SecurityInsights/onboardingStates/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "e8c1770a-aacc-9124-6d50-abe842c48467",
    "eventSubmissionTimestamp": "2026-07-02T16:09:23.9378579Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/default",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/register/action

#
Namespace
Microsoft.SecurityInsights

Description

Registers the subscription to Azure Sentinel

References #

Microsoft.SecurityInsights/securityMLAnalyticsSettings/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete an analytics setting

References #

Microsoft.SecurityInsights/securityMLAnalyticsSettings/write

#
Namespace
Microsoft.SecurityInsights

Description

Update the analytics settings

References #

Microsoft.SecurityInsights/settings/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes setting

References #

Microsoft.SecurityInsights/settings/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates settings

References #

Microsoft.SecurityInsights/SourceControls/delete

#
Namespace
Microsoft.SecurityInsights

Description

Delete SourceControls

References #

Microsoft.SecurityInsights/SourceControls/write

#
Namespace
Microsoft.SecurityInsights

Description

write SourceControls

References #

Microsoft.SecurityInsights/threatintelligence/bulkactions/count/action

#
Namespace
Microsoft.SecurityInsights

Description

Query Threat Intelligence STIX object count

References #

Microsoft.SecurityInsights/threatintelligence/bulkactions/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a TI Bulk Action

References #

Microsoft.SecurityInsights/threatintelligence/bulkactions/query/action

#
Namespace
Microsoft.SecurityInsights

Description

Query Threat Intelligence STIX objects

References #

Microsoft.SecurityInsights/threatintelligence/bulkactions/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates or updates a TI Bulk Action

References #

Microsoft.SecurityInsights/threatintelligence/bulkDelete/action

#
Namespace
Microsoft.SecurityInsights

Description

Bulk Delete Threat Intelligence

References #

Microsoft.SecurityInsights/threatintelligence/bulkTag/action

#
Namespace
Microsoft.SecurityInsights

Description

Bulk Tags Threat Intelligence

References #

Microsoft.SecurityInsights/threatintelligence/createIndicator/action

#
Namespace
Microsoft.SecurityInsights

Description

Create Threat Intelligence Indicator

References #

Microsoft.SecurityInsights/threatintelligence/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Threat Intelligence

References #

Microsoft.SecurityInsights/threatintelligence/indicators/appendTags/action

#
Namespace
Microsoft.SecurityInsights

Description

Append tags to Threat Intelligence Indicator

References #

Microsoft.SecurityInsights/threatintelligence/indicators/bulkDelete/action

#
Namespace
Microsoft.SecurityInsights

Description

Bulk Delete Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/indicators/bulkTag/action

#
Namespace
Microsoft.SecurityInsights

Description

Bulk Tags Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/indicators/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/indicators/metrics/action

#
Namespace
Microsoft.SecurityInsights

Description

Get Threat Intelligence Indicator Metrics

References #

Microsoft.SecurityInsights/threatintelligence/indicators/query/action

#
Namespace
Microsoft.SecurityInsights

Description

Query Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/indicators/replaceTags/action

#
Namespace
Microsoft.SecurityInsights

Description

Replace Tags of Threat Intelligence Indicator

References #

Microsoft.SecurityInsights/threatintelligence/indicators/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/ingestionrulelist/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates or updates a set of TI Ingestion Rules

References #

Microsoft.SecurityInsights/threatintelligence/metrics/action

#
Namespace
Microsoft.SecurityInsights

Description

Collect Threat Intelligence Metrics

References #

Microsoft.SecurityInsights/threatintelligence/query/action

#
Namespace
Microsoft.SecurityInsights

Description

Query Threat Intelligence

References #

Microsoft.SecurityInsights/threatintelligence/queryIndicators/action

#
Namespace
Microsoft.SecurityInsights

Description

Query Threat Intelligence Indicators

References #

Microsoft.SecurityInsights/threatintelligence/threatactors/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes a TI Threat Actor

References #

Microsoft.SecurityInsights/threatintelligence/threatactors/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates or updates a TI Threat Actor

References #

Microsoft.SecurityInsights/threatintelligence/write

#
Namespace
Microsoft.SecurityInsights

Description

Updates Threat Intelligence

References #

Microsoft.SecurityInsights/unregister/action

#
Namespace
Microsoft.SecurityInsights

Description

Unregisters the subscription from Azure Sentinel

References #

Microsoft.SecurityInsights/Watchlists/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes Watchlists

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "action": "Microsoft.SecurityInsights/watchlists/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "action": "Microsoft.SecurityInsights/watchlists/delete",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "12f52614-d0b5-4b3d-a24a-3bc158e38c6b",
  "EventDataId": "a8d900c3-920d-be9c-c723-fb4dc8f8e242",
  "EventSubmissionTimestamp": "2026-07-04T15:08:17.7777691Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/WATCHLISTS/DELETE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "message": "Microsoft.SecurityInsights/watchlists/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a8d900c3-920d-be9c-c723-fb4dc8f8e242",
    "eventSubmissionTimestamp": "2026-07-04T15:08:17.7777691Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/dwharn-wl-2010e6cb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "message": "Microsoft.SecurityInsights/watchlists/delete",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a8d900c3-920d-be9c-c723-fb4dc8f8e242",
    "eventSubmissionTimestamp": "2026-07-04T15:08:17.7777691Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/dwharn-wl-2010e6cb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/Watchlists/write

#
Namespace
Microsoft.SecurityInsights

Description

Create Watchlists

Example Resource Log Record #

{
  "ActivityStatusValue": "Success",
  "ActivitySubstatusValue": "OK",
  "Authorization": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "action": "Microsoft.SecurityInsights/watchlists/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Authorization_d": {
    "scope": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "action": "Microsoft.SecurityInsights/watchlists/write",
    "evidence": {
      "role": "Owner",
      "roleAssignmentScope": "/subscriptions/22222222-2222-2222-2222-222222222222",
      "roleAssignmentId": "0614d5b6f6da4638b65970d8138290c0",
      "roleDefinitionId": "8e3af657a8ff443ca75c2fe8c4bcb635",
      "principalId": "aaaaaaaa000000000000000000000001",
      "principalType": "User"
    }
  },
  "Caller": "adminuser@example.onmicrosoft.com",
  "CallerIpAddress": "203.0.113.10",
  "CategoryValue": "Administrative",
  "Claims": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "idtyp": "user",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "puid": "1111111111111111",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282"
  },
  "Claims_d": {
    "aud": "https://management.core.windows.net/",
    "iss": "https://sts.windows.net/11111111-1111-1111-1111-111111111111/",
    "iat": "1783177024",
    "nbf": "1783177024",
    "exp": "1783181345",
    "aio": "AXQAi/8cAAAAKi8/A8NhZZ93PFnxLuhwYDXi1rFTdM43nSP09F91g0vuuY4fh/32Gk5fhAftbqGURQuBeAChb8s5Vh76gGR9/BtuqJP9O73HNLyE17sTgd891CB/phNIP0PhmDfitOQJjgafTHE0Rg4sWOe7CIqO6A==",
    "appid": "04b07795-8ddb-461a-bbee-02f9e1bf7b46",
    "appidacr": "0",
    "idtyp": "user",
    "http://schemas.microsoft.com/identity/claims/objectidentifier": "aaaaaaaa-0000-0000-0000-000000000001",
    "rh": "1.AXgA2MxkHpDbsUq-nMBN5yQeykZIf3kAutdPukPawfj2MBMBAM54AA.",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier": "59zMO99J0dkUCRNy4Ijj09ztqIlC6EL2p5Qt9PVxzvM",
    "http://schemas.microsoft.com/identity/claims/tenantid": "11111111-1111-1111-1111-111111111111",
    "uti": "I73cB--4LUynbk58Lw4JAA",
    "ver": "1.0",
    "wids": "62e90394-69f5-4237-9190-012177145e10,b79fbf4d-3ef9-4689-8143-76b194e85509",
    "xms_act_fct": "5 3",
    "xms_ftd": "jXCr80rgkyIHATRhtB8cxis-u-GQBovvTVgGAZGNTh8BdXNlYXN0LWRzbXM",
    "xms_idrel": "6 1",
    "xms_sub_fct": "3 14",
    "xms_tcdt": "1768616282",
    "groups": "7e349a88-0f5b-4e6e-b331-4ecd314e4e20",
    "http://schemas.microsoft.com/claims/authnclassreference": "1",
    "acrs": "p1",
    "http://schemas.microsoft.com/claims/authnmethodsreferences": "pwd,mfa",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname": "User",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "Admin",
    "ipaddr": "203.0.113.10",
    "name": "Admin User",
    "puid": "1111111111111111",
    "http://schemas.microsoft.com/identity/claims/scope": "user_impersonation",
    "sid": "0022840a-e4ab-884c-587f-d20d24637227",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name": "adminuser@example.onmicrosoft.com",
    "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn": "adminuser@example.onmicrosoft.com"
  },
  "CorrelationId": "8c90e949-bf31-4eb7-a417-362409272df0",
  "EventDataId": "a889688a-7369-c31f-00e2-633ba66dc055",
  "EventSubmissionTimestamp": "2026-07-04T15:08:14.0505371Z",
  "HTTPRequest": {
    "clientIpAddress": "203.0.113.10"
  },
  "Hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
  "Level": "Information",
  "OperationNameValue": "MICROSOFT.SECURITYINSIGHTS/WATCHLISTS/WRITE",
  "Properties": {
    "statusCode": "OK",
    "serviceRequestId": "",
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "message": "Microsoft.SecurityInsights/watchlists/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a889688a-7369-c31f-00e2-633ba66dc055",
    "eventSubmissionTimestamp": "2026-07-04T15:08:14.0505371Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/dwharn-wl-2010e6cb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "activitySubstatusValue": "OK"
  },
  "Properties_d": {
    "eventCategory": "Administrative",
    "entity": "/subscriptions/22222222-2222-2222-2222-222222222222/resourceGroups/rg-logcapture-gen/providers/Microsoft.OperationalInsights/workspaces/dw-live-schema-ws/providers/Microsoft.SecurityInsights/watchlists/dwharn-wl-2010e6cb",
    "message": "Microsoft.SecurityInsights/watchlists/write",
    "hierarchy": "11111111-1111-1111-1111-111111111111/22222222-2222-2222-2222-222222222222",
    "caller": "adminuser@example.onmicrosoft.com",
    "eventDataId": "a889688a-7369-c31f-00e2-633ba66dc055",
    "eventSubmissionTimestamp": "2026-07-04T15:08:14.0505371Z",
    "httpRequest": {
      "clientIpAddress": "203.0.113.10"
    },
    "resource": "dw-live-schema-ws/microsoft.securityinsights/dwharn-wl-2010e6cb",
    "resourceGroup": "rg-logcapture-gen",
    "resourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
    "subscriptionId": "22222222-2222-2222-2222-222222222222",
    "activityStatusValue": "Success",
    "statusCode": "OK",
    "serviceRequestId": "",
    "activitySubstatusValue": "OK"
  },
  "ResourceGroup": "rg-logcapture-gen",
  "ResourceProviderValue": "MICROSOFT.OPERATIONALINSIGHTS",
  "SubscriptionId": "22222222-2222-2222-2222-222222222222"
}

References #

Microsoft.SecurityInsights/WorkspaceManagerAssignments/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes WorkspaceManager Assignments

References #

Microsoft.SecurityInsights/workspaceManagerAssignments/jobs/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes WorkspaceManagerAssignments jobs

References #

Microsoft.SecurityInsights/workspaceManagerAssignments/jobs/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates WorkspaceManagerAssignments jobs

References #

Microsoft.SecurityInsights/WorkspaceManagerAssignments/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates WorkspaceManager Assignments

References #

Microsoft.SecurityInsights/WorkspaceManagerConfigurations/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes WorkspaceManager Configurations

References #

Microsoft.SecurityInsights/WorkspaceManagerConfigurations/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates WorkspaceManager Configurations

References #

Microsoft.SecurityInsights/WorkspaceManagerGroups/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes WorkspaceManager Groups

References #

Microsoft.SecurityInsights/WorkspaceManagerGroups/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates WorkspaceManager Groups

References #

Microsoft.SecurityInsights/WorkspaceManagerMembers/delete

#
Namespace
Microsoft.SecurityInsights

Description

Deletes WorkspaceManager Members

References #

Microsoft.SecurityInsights/WorkspaceManagerMembers/write

#
Namespace
Microsoft.SecurityInsights

Description

Creates WorkspaceManager Members

References #