defender_add_alert_comment
Append a comment to an alert's thread in the Defender portal for analyst visibility. Use for triage notes; keep incident-level case notes on the incident.
Instructions
Append a comment to an alert's comment thread (a triage write), visible to analysts in the Defender portal. Notes about the whole case belong on the incident instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| comment | Yes | The comment text to append to the thread. | |
| alert_id | Yes | The alert ID. |