POWERSHELL COMMAND
Move-XdrAlertToIncident
Moves alerts to a specific incident or creates a new one.
Moves one or more alerts to a target incident. If TargetIncidentId is not specified, a new incident is created containing the alerts. Validates that the TargetIncidentId and AlertIds exist before attempting the move.
Syntax
Move-XdrAlertToIncident [-AlertIds] <string[]> [[-TargetIncidentId] <long>] [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-AlertIds
| Property | Value |
|---|---|
| Type | String[] |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue) |
| Default | Not documented |
A list of alert IDs to move.
-TargetIncidentId
| Property | Value |
|---|---|
| Type | Int64 |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | 0 |
The ID of the incident to move the alerts to. If null or omitted, a new incident is created.
-Comment
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Moved via XDRInternals |
Optional comment for the operation. Default is “Moved via XDRInternals”.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before executing the move operation.
Examples
Move-XdrAlertToIncident -AlertIds "ed638962183442188554_-691007355" -TargetIncidentId 2822
Moves the specified alert to incident 2822.
Move-XdrAlertToIncident -AlertIds "ed638962183442188554_-691007355"
Moves the specified alert to a new incident.
Output
Type: System.Management.Automation.PSObject