<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get Incident List from Microsoft 365 Defender in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/get-incident-list-from-microsoft-365-defender/m-p/595063#M3529</link>
    <description>&lt;P&gt;That's the neat part: you can't!&lt;BR /&gt;&lt;BR /&gt;In the reference documentation for the 365 Defender integration, for the "incidents-list" command the default, and maximum, is 100.&lt;BR /&gt;You can change it to be less, but not more.&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender#microsoft-365-defender-incidents-list" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender#microsoft-365-defender-incidents-list&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 22:48:04 GMT</pubDate>
    <dc:creator>cmcneil</dc:creator>
    <dc:date>2024-08-15T22:48:04Z</dc:date>
    <item>
      <title>Get Incident List from Microsoft 365 Defender</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/get-incident-list-from-microsoft-365-defender/m-p/592887#M3495</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I want to get the events between the dates I give from Microsoft 356 Defender. In the ‘microsoft-365-defender-incidents-list’ command, the limit is set to maximum 100. What should I do to make the limit unlimited?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The command: &lt;/P&gt;
&lt;LI-CODE lang="python"&gt;test_data ={’$filter": “createdTime gt 2024-03-16T06:00:00.29Z and createdTime lt 2024-07-22T09:00:00.29Z”}
execute_command(‘microsoft-365-defender-incidents-list’, {‘status’: ‘Resolved’, ‘odata’:test_data})&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;In addition, I can send the current query according to the created time from the incoming data, but I want to learn if there is a known method such as limit=-1, not with a loop.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;#Microsoft365Defender &lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:51:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/get-incident-list-from-microsoft-365-defender/m-p/592887#M3495</guid>
      <dc:creator>E.Ok204121</dc:creator>
      <dc:date>2024-07-24T13:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Get Incident List from Microsoft 365 Defender</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/get-incident-list-from-microsoft-365-defender/m-p/595063#M3529</link>
      <description>&lt;P&gt;That's the neat part: you can't!&lt;BR /&gt;&lt;BR /&gt;In the reference documentation for the 365 Defender integration, for the "incidents-list" command the default, and maximum, is 100.&lt;BR /&gt;You can change it to be less, but not more.&lt;BR /&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender#microsoft-365-defender-incidents-list" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender#microsoft-365-defender-incidents-list&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 22:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/get-incident-list-from-microsoft-365-defender/m-p/595063#M3529</guid>
      <dc:creator>cmcneil</dc:creator>
      <dc:date>2024-08-15T22:48:04Z</dc:date>
    </item>
  </channel>
</rss>

