defender_get_investigations
Retrieve automated investigations with their current state and the alert that triggered each.
Instructions
List automated investigations with their state and the alert that triggered each.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | Maximum number of investigations to return (default 25, max 100). | |
| skip | No | Number of entries to skip (paging). | |
| filter | No | OData $filter expression. Refine the filter instead of paging deep. |