Microsoft Graph API missing data

%3CLINGO-SUB%20id%3D%22lingo-sub-1456484%22%20slang%3D%22en-US%22%3EMicrosoft%20Graph%20API%20missing%20data%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1456484%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20using%20the%20Graph%20API%20to%20try%20to%20query%20the%20incidents%20in%20Sentinel%2C%20however%20not%20all%20of%20the%20data%20is%20populating%20properly.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20data%20that%20is%20especially%20useful%20for%20the%20purpose%20of%20this%20API%20call%20is%20the%20following%2C%20yet%20they%20are%20all%20appearing%20as%20null.%20When%20in%20reality%2C%20they%20should%20be%20populated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFields%20appearing%20as%20null%3A%3C%2FP%3E%3CUL%3E%3CLI%3EClosedDateTime%26nbsp%3B%3C%2FLI%3E%3CLI%3EComments%3C%2FLI%3E%3CLI%3EAssigned%3C%2FLI%3E%3CLI%3EStatus%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1458699%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Graph%20API%20missing%20data%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1458699%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3BA%20couple%20of%20things%3C%2FP%3E%3CP%3E1)%20The%20Microsoft%20Graph%20API%20only%20returns%20alerts%2C%20not%20incidents.%26nbsp%3B%20I%20have%20been%20looking%20into%20the%20same%20issue%20when%20using%20the%20ServiceNow%20Graph%20API%20connector.%3C%2FP%3E%3CP%3E2)%20Cannot%20go%20into%20much%20detail%20but%20your%20question%20may%20be%20moot%20very%20soon%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1459009%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Graph%20API%20missing%20data%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1459009%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F418279%22%20target%3D%22_blank%22%3E%40leoszalkowski%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20are%20happy%20to%20use%20an%20api%20you%20can%20use%20the%20Azure%20Sentinel%20api%20(preview)%2C%20like%20I%20show%20here%20(I%20use%20a%20Workbook%20but%20you%20can%20use%20your%20preferred%20tool)%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusing-the-sentinel-api-to-view-data-in-a-workbook%2Fba-p%2F1386436%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusing-the-sentinel-api-to-view-data-in-a-workbook%2Fba-p%2F1386436%3C%2FA%3E%26nbsp%3Band%20as%20Gary%20alludes%20to%2C%20things%20are%20planned%20for%20Incidents%20-%20more%20news%20soon%26nbsp%3B%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3EDirect%20link%20to%20latest%20version%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FCliveW-MSFT%2FKQLpublic%2Fblob%2Fmaster%2FKQL%2FWorkbooks%2Fapi%2520test%2520v1.4.2.workbook%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FCliveW-MSFT%2FKQLpublic%2Fblob%2Fmaster%2FKQL%2FWorkbooks%2Fapi%2520test%2520v1.4.2.workbook%3C%2FA%3E%26nbsp%3Bwhich%20allows%20you%20to%20filter%20to%20see%20Comments%2C%20Bookmarks%20are%20in%20a%20seperate%20api.%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorClive%20Watson_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Annotation%202020-06-12%20131036.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F198358iA7D8FB7BDA9EBBBB%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Annotation%202020-06-12%20131036.jpg%22%20alt%3D%22Annotation%202020-06-12%20131036.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1463333%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Graph%20API%20missing%20data%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1463333%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F239477%22%20target%3D%22_blank%22%3E%40Clive%20Watson%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAwesome%2C%20thanks%20for%20the%20information%20guys!%20I'll%20test%20this%20out%20this%20week%20and%20see%20how%20it%20performs.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan't%20wait%20to%20hear%20the%20news.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

I'm using the Graph API to try to query the incidents in Sentinel, however not all of the data is populating properly.

 

The data that is especially useful for the purpose of this API call is the following, yet they are all appearing as null. When in reality, they should be populated.

 

Fields appearing as null:

  • ClosedDateTime 
  • Comments
  • Assigned
  • Status

 

3 Replies

@leoszalkowski A couple of things

1) The Microsoft Graph API only returns alerts, not incidents.  I have been looking into the same issue when using the ServiceNow Graph API connector.

2) Cannot go into much detail but your question may be moot very soon

@Gary Bushey 

@leoszalkowski 

 

If you are happy to use an api you can use the Azure Sentinel api (preview), like I show here (I use a Workbook but you can use your preferred tool): https://techcommunity.microsoft.com/t5/azure-sentinel/using-the-sentinel-api-to-view-data-in-a-workb... and as Gary alludes to, things are planned for Incidents - more news soon  

Direct link to latest version: https://github.com/CliveW-MSFT/KQLpublic/blob/master/KQL/Workbooks/api%20test%20v1.4.2.workbook which allows you to filter to see Comments, Bookmarks are in a seperate api.

 

Annotation 2020-06-12 131036.jpg

@Clive Watson @Gary Bushey 

 

Awesome, thanks for the information guys! I'll test this out this week and see how it performs. 

 

Can't wait to hear the news.