defender_get_machine_alerts
Retrieve the security alerts associated with a specific device in Microsoft Defender for Endpoint, using optional filters to narrow results.
Instructions
List the Defender for Endpoint alerts of one device.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | Maximum number of alerts to return (default 25, max 100). | |
| filter | No | OData $filter expression. Refine the filter instead of paging deep. | |
| machine_id | Yes | The Defender for Endpoint machine (device) ID. |