Forum Discussion
Cristhofer Munoz
Microsoft
Nov 11, 2020What's New: Tags column is now available in Azure Sentinel incidents page!
Hello everyone,
We are happy to share with you a small but important improvement we added to our incidents blade – a new tag column is now available as part of the Incidents list!
Tags are...
Clive_Watson
Feb 07, 2023Bronze Contributor
Labels == Tags
SecurityIncident
| extend Tags = parse_json(Labels)
| extend labelName_ = tostring(Tags[0].labelName)
| where isnotempty(labelName_)
Patclementine
Jan 17, 2024Copper Contributor
Hi Clive
I was reading though the documentation on how to create a Sentinel Incident with API but unfortunately I am not able to add labels/tags while creating a Sentinel Incident Manually with API Payload
any suggestions I could try?
- GBusheyJan 17, 2024Former EmployeeThey are referred to as "labels" in the REST API documentation. I have an example with them in my Sentinel development EBook: https://garybushey.com/2023/11/27/programming-book-version-1-0-finally-ready/
- PatclementineJan 17, 2024Copper Contributor
Hello
thank you for the link I tried that and I am receiving some error like below:
Bad Request: Error converting value [] to type Microsoft.Azure.Sentinel.CasesArmApi.Controllers.Stable.Version_2020_01_01.IncidentLabelArmModel
P.S. I am using the 2023 api version
not sure what is the reason as I have my code in Python
- GBusheyJan 17, 2024Former EmployeeNot sure how to make Python create a JSON array of labels, but does each entry you create have a "labelName" and "labelType"?