Share via

Sentinel Analytics Rule not creating incident

Conor Bateman (Alcom IT) 5 Reputation points
2025-02-26T14:51:55.7166667+00:00

I have worked with Microsoft Support and created an Analytics rule to raise an incident when 5 or more failed login attempts are detected, followed by a success.

This worked originally but has now stopped working.

Nothing has changed. I cannot figure out why this could have stopped working.

Microsoft Security | Microsoft Sentinel

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 10,071 Reputation points Microsoft Employee
    2025-02-27T12:45:43.73+00:00

    Agreed. We will need more information to assist. I recommend copying the rule query into Log Analytics to run or use the test option 'runs' on the rule. When testing the query independently, try commenting out the threshold, any parameters, and possibly the project statement. Look to verify that the underlying data is present. Verify that the lookback timespan is sufficient.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.