Skip to content

Missing POST method for /security/incident/{incidentId}/comments #624

Description

@nmourad

SDK method is missing to add comment on an incident
Corresponding doc : https://learn.microsoft.com/en-us/graph/api/security-incident-post-comments?view=graph-rest-1.0&tabs=http

Activity

  1. shemogumbe commented on Aug 23, 2024

    @shemogumbe
    Contributor

    Hello nmourad thanks for using the SDK and for raising this.

    This method actually exists as you can see from https://github.com/microsoftgraph/msgraph-sdk-python/blob/main/msgraph/generated/security/incidents/item/alerts/item/comments/comments_request_builder.py

    mappig to the URL call https://graph.microsoft.com/v1.0/security/incidents/{incident-id}/alerts/{alert-id}/comments

    It can be used via a snippet like:

    post_body = 
    result = await graph_client.security.incidents.by_incident_id("id").alterts.by_alert_id('id).comments.post(post_body )

    Also Check that your account is provisioned and appropriate permisions are assigned

  2. nmourad commented on Aug 23, 2024

    @nmourad
    Author

    Hello,
    This method exists indeed for alerts linked to an incident but not to directly comment on an Incident that can have n alerts (like i mentioned on my issue report)
    Doing what's below I've been able to make it work and put a comment on the incident directly (not on the alerts in the incident) so this method exist at incident level (also mentioned on this doc : https://learn.microsoft.com/en-us/graph/api/security-incident-post-comments?view=graph-rest-1.0&tabs=http

        inc_req_builder = graph_client.security.incidents
    
        await inc_req_builder.with_url(
            "https://graph.microsoft.com/v1.0/security/incidents/" + incident.id + "/comments"
        ).post(AlertComment(comment=comment))
    
  3. removed their assignment
    on Aug 23, 2024
  4. locked and limited conversation to collaborators on Aug 26, 2024
  5. converted this issue into a discussion #875 on Aug 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions