Class: MicrosoftGraph::Security::Incidents::IncidentsRequestBuilder::IncidentsRequestBuilderGetQueryParameters

Inherits:
Object
  • Object
show all
Defined in:
lib/security/incidents/incidents_request_builder.rb

Overview

Get a list of incident objects that Microsoft 365 Defender has created to track attacks in an organization. Attacks are typically inflicted on different types of entities, such as devices, users, and mailboxes, resulting in multiple alert objects. Microsoft 365 Defender correlates alerts with the same attack techniques or the same attacker into an incident. This operation allows you to filter and sort through incidents to create an informed cyber security response. It exposes a collection of incidents that were flagged in your network, within the time range you specified in your environment retention policy. The most recent incidents are displayed at the top of the list.

Instance Attribute Summary collapse

Instance Method Summary collapse

Instance Attribute Details

#countObject

Include count of items



118
119
120
# File 'lib/security/incidents/incidents_request_builder.rb', line 118

def count
  @count
end

#expandObject

Expand related entities



121
122
123
# File 'lib/security/incidents/incidents_request_builder.rb', line 121

def expand
  @expand
end

#filterObject

Filter items by property values



124
125
126
# File 'lib/security/incidents/incidents_request_builder.rb', line 124

def filter
  @filter
end

#orderbyObject

Order items by property values



127
128
129
# File 'lib/security/incidents/incidents_request_builder.rb', line 127

def orderby
  @orderby
end

#searchObject

Search items by search phrases



130
131
132
# File 'lib/security/incidents/incidents_request_builder.rb', line 130

def search
  @search
end

#selectObject

Select properties to be returned



133
134
135
# File 'lib/security/incidents/incidents_request_builder.rb', line 133

def select
  @select
end

#skipObject

Skip the first n items



136
137
138
# File 'lib/security/incidents/incidents_request_builder.rb', line 136

def skip
  @skip
end

#topObject

Show only the first n items



139
140
141
# File 'lib/security/incidents/incidents_request_builder.rb', line 139

def top
  @top
end

Instance Method Details

#get_query_parameter(original_name) ⇒ Object

Maps the query parameters names to their encoded names for the URI template parsing.

Parameters:

  • original_name

    The original query parameter name in the class.

Returns:

  • a string

Raises:

  • (StandardError)


145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
# File 'lib/security/incidents/incidents_request_builder.rb', line 145

def get_query_parameter(original_name)
    raise StandardError, 'original_name cannot be null' if original_name.nil?
    case original_name
        when "count"
            return "%24count"
        when "expand"
            return "%24expand"
        when "filter"
            return "%24filter"
        when "orderby"
            return "%24orderby"
        when "search"
            return "%24search"
        when "select"
            return "%24select"
        when "skip"
            return "%24skip"
        when "top"
            return "%24top"
        else
            return original_name
    end
end