
I would think that incidents only would be an option. Can you recount how the ArcSight integration was setup initially? You can stream these alerts and incidents to Sentinel at no additional cost. Once option would be to link M365D to a Sentinel instance (just for this purpose). This could reveal additional options for ArcSight integration with more filtering options. For example, use the workspace data export to send the incidents table to an event hub.