What are “Incidents” in Azure Sentinel and how are they different from alerts?

Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
2020-05-06T20:45:18.433+00:00

What does it mean when I see a list of new and open incidents in Azure Sentinel? What are incidents in Azure Sentinel and how are they different from alerts?

7916-incidents-sentinel.png

[Note: As we migrate from MSDN, this question has been posted by an Azure Cloud Engineer as a frequently asked question] Source: Azure Sentinel Overview

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. Saurabh Sharma 23,851 Reputation points Microsoft Employee Moderator
    2020-05-06T20:54:01.373+00:00

    Incidents are groups of related alerts that together create an actionable possible-threat that you can investigate and resolve. Azure Sentinel uses analytics to correlate alerts into incidents. Use the built-in correlation rules as-is, or use them as a starting point to build your own.
    Azure Sentinel also provides machine learning rules to map your network behavior and then look for anomalies across your resources. These analytics connect the dots, by combining low fidelity alerts about different entities into potential high-fidelity security incidents.

    Source: https://learn.microsoft.com/en-us/azure/sentinel/overview

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.