← All XDRInternals commands

POWERSHELL COMMAND

Merge-XdrIncident

Merges multiple incidents into a single incident in Microsoft Defender XDR.

View source ↗

Combines multiple incidents into one incident in Microsoft Defender XDR. All incidents must exist before merging. The cmdlet validates each incident ID before proceeding. This operation requires confirmation due to its high impact.

Syntax

Merge-XdrIncident [-IncidentIds] <int[]> [-Comment] <string> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-IncidentIds

Property Value
Type Int32[]
Required Yes
Position 1
Pipeline input No
Default Not documented

Array of incident IDs to merge. Must contain at least 2 incident IDs. All incidents will be validated before the merge operation.

-Comment

Property Value
Type String
Required Yes
Position 2
Pipeline input No
Default Not documented

Comment explaining the reason for merging the incidents. This will be recorded in the incident history.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The JSON body for the merge operation will be displayed.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before executing the merge operation.

Examples

Merge-XdrIncident -IncidentIds 2821, 2823 -Comment "Related phishing attacks"
Merges incidents 2821 and 2823 with a comment.
Merge-XdrIncident -IncidentIds 100, 101, 102 -Comment "Same threat actor campaign"
Merges three incidents into one.
$incidents = 2821, 2823, 2825
Merge-XdrIncident -IncidentIds $incidents -Comment "Coordinated attack"
Merges multiple incidents using a variable.

Output

Type: Object

Returns the result of the merge operation from the API.

View source