Sentinel incident trigger

Minghui Zou 186 Reputation points
2021-09-11T07:48:31.227+00:00

Hi folks

I’m new to sentinel, after going through the documentation I have a few questions regarding the incident trigger.
So, According to the Microsoft sentinel Documentation
“Playbooks with this trigger do not support alert grouping, meaning they will receive only the first alert sent with each incident. ”

Why the incident trigger do not support alert grouping and why they will only receive the first alert. Thank you so much, I just can’t get my head around with this concept.
Cheers

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,316 Reputation points Microsoft Employee Moderator
    2021-09-13T05:02:09.86+00:00

    @Minghui Zou Thanks for reaching out.

    This is more of a known limitation and Product group might make some changes in future.
    You can always always use the alert trigger to group the alerts and perform automation.

    Do you have any specific scenario in mind which is causing the road blocker ?

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.