Forum Discussion
MS Defender XDR API missing Alerts
The Microsoft Defender XDR API is missing Alerts that are visible in the console (https://security.microsoft.com). The number of Alerts returned by the Incident API is limits to 150. This information is no where in the documentation. If you have an Incident with greater than 150 Alerts, the API will not provide all the Alerts for a given Incident.
https://learn.microsoft.com/en-us/defender-xdr/api-list-incidents
My team has confirmed this behavior across hundreds of tenants and thousands of Incidents. MS Premier Support has not been helpful in understanding if this is a known issue or a bug.
Has anyone encountered this issue and have any information?
Obviously closing the Incident will solve the problem, but for ongoing investigations this is not alway an option.