API Call Results for Microsoft Defender for Endpoint

Microsoft Defender for Endpoint line

Details

IDAPI Call Results for Microsoft Defender for Endpoint
Widget Typeline
Data Typemetrics
From Version6.8.0
PredefinedYes
Supported Modulesagentix xsiam

Query

type:integration and instance:"Microsoft Defender Advanced Threat Protection_instance_1"
{
    "dataType": "metrics",
    "params": {
        "customGroupBy": [
            null,
            {
                "General Error": {
                    "conditions": [
                        [
                            {
                                "field": "apiResponseType",
                                "operator": "isEqualCaseString",
                                "right": "GeneralError",
                                "type": "string"
                            }
                        ]
                    ],
                    "name": "General Error"
                },
                "Quota Error": {
                    "conditions": [
                        [
                            {
                                "field": "apiResponseType",
                                "operator": "isEqualCaseString",
                                "right": "QuotaError",
                                "type": "string"
                            }
                        ]
                    ],
                    "name": "Quota Error"
                },
                "Success": {
                    "conditions": [
                        [
                            {
                                "field": "apiResponseType",
                                "operator": "isEqualCaseString",
                                "right": "Successful",
                                "type": "string"
                            }
                        ]
                    ],
                    "name": "Success"
                }
            }
        ],
        "groupBy": [
            "modified(h)",
            "apiResponseType"
        ],
        "keys": [
            "sum|totalAPICalls"
        ],
        "referenceLine": {},
        "timeFrame": "hours",
        "valuesFormat": "abbreviated",
        "xAxisLabel": "Time",
        "yAxisLabel": "Request Counts"
    },
    "query": "type:integration and instance:\"Microsoft Defender Advanced Threat Protection_instance_1\"",
    "modified": "2022-04-27T15:34:53.64268093Z",
    "name": "API Call Results for Microsoft Defender for Endpoint",
    "dateRange": {
        "fromDate": "0001-01-01T00:00:00Z",
        "toDate": "0001-01-01T00:00:00Z",
        "period": {
            "by": "",
            "byTo": "days",
            "byFrom": "hours",
            "toValue": 0,
            "fromValue": 3,
            "field": ""
        },
        "fromDateLicense": "0001-01-01T00:00:00Z"
    },
    "isPredefined": true,
    "version": -1,
    "widgetType": "line",
    "fromVersion": "6.8.0",
    "id": "API Call Results for Microsoft Defender for Endpoint",
    "description": "",
    "supportedModules": [
        "agentix",
        "xsiam"
    ]
}