Forum Discussion

CharlieSmith555's avatar
CharlieSmith555
Copper Contributor
Jun 17, 2021

Azure Sentinel Bookmark API entities

I'm having problems understanding how to map entities using Azure Sentinel Bookmarks via API.

 

I can easily map entities when I manually create a bookmark (see screen shot below)

 

However when I create a Bookmark via API (found https://docs.microsoft.com/en-us/rest/api/securityinsights/bookmarks/create-or-update#request-body), I don't see or how I can map entities. Instead the contents of the Bookmark appear blank (see screen shot below)

 

The KQL query I'm using is basic (which would generate results), more or less I'm using this as a test

 

Is there anything I'm missing or doing wrong?

 

2 Replies

Resources