Add Location as an Entity in Sentinel alerting

Paul Roche 0 Reputation points
2023-06-12T07:41:56.9033333+00:00

Hi,

I am currently trying to make an alert that detects successful authentications from a country the user has not signed in from before. While setting up this alert I have not found an option to add Entity mapping for the Location field.

Is there a way to be able to add this into the alert as this would help prevent duplicate alerts and provide more information straight away when the alert is raised.

Thanks

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Clive Watson 7,951 Reputation points MVP Volunteer Moderator
    2023-06-12T09:24:31.6933333+00:00

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.