POWERSHELL COMMAND
Get-XdrIncidentAssociatedAlert
Retrieves alerts associated with a specific incident from Microsoft Defender XDR.
Gets all alerts associated with a specific incident ID from Microsoft Defender XDR. This cmdlet automatically handles pagination to retrieve all associated alerts. The results are cached to improve performance.
Syntax
Get-XdrIncidentAssociatedAlert [-IncidentId] <int> [-Force] [<CommonParameters>]
Parameters
-IncidentId
| Property | Value |
|---|---|
| Type | Int32 |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | 0 |
The ID of the incident to retrieve associated alerts for.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIncidentAssociatedAlert -IncidentId 2824
Retrieves all alerts associated with incident 2824.
Output
Type: Object[]
Returns an array of alert objects associated with the incident.