defender_get_ip_alerts
List Microsoft Defender for Endpoint alerts involving an IP address to investigate security incidents. Refine results with optional filters for targeted analysis.
Instructions
List the Defender for Endpoint alerts that involve an IP address.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | Yes | IP address. | |
| top | No | Maximum number of alerts to return (default 25, max 100). | |
| filter | No | OData $filter expression. Refine the filter instead of paging deep. |