← All XDRInternals commands

POWERSHELL COMMAND

Move-XdrAlertToIncident

Moves alerts to a specific incident or creates a new one.

View source ↗

Moves one or more alerts to a target incident. If TargetIncidentId is not specified, a new incident is created containing the alerts. Validates that the TargetIncidentId and AlertIds exist before attempting the move.

Syntax

Move-XdrAlertToIncident [-AlertIds] <string[]> [[-TargetIncidentId] <long>] [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-AlertIds

Property Value
Type String[]
Required Yes
Position 1
Pipeline input true (ByValue)
Default Not documented

A list of alert IDs to move.

-TargetIncidentId

Property Value
Type Int64
Required No
Position 2
Pipeline input No
Default 0

The ID of the incident to move the alerts to. If null or omitted, a new incident is created.

-Comment

Property Value
Type String
Required No
Position 3
Pipeline input No
Default Moved via XDRInternals

Optional comment for the operation. Default is “Moved via XDRInternals”.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before executing the move operation.

Examples

Move-XdrAlertToIncident -AlertIds "ed638962183442188554_-691007355" -TargetIncidentId 2822
Moves the specified alert to incident 2822.
Move-XdrAlertToIncident -AlertIds "ed638962183442188554_-691007355"
Moves the specified alert to a new incident.

Output

Type: System.Management.Automation.PSObject

View source