Cannot view Sentinel alert for some incidents but the alert can be found in Defender for Endpoint portal using Graph

Spyros Ermogenous 0 Reputation points
2024-03-12T07:17:33.5466667+00:00

I have enabled automatic incident creation for Defender for Endpoint in Sentinel but when I try to view some alerts associated with the created incidents, nothing is displayed. Despite this, I can locate the relevant alert in the Security (Defender for Endpoint) portal through Graph API, even though it has a different AlertID.

How can I establish a connection between these two alerts?

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,614 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
979 questions
{count} votes