Sentinel incident trigger

Minghui Zou 186 Reputation points
2021-09-11T07:48:31.227+00:00

Hi folks

I’m new to sentinel, after going through the documentation I have a few questions regarding the incident trigger.
So, According to the Microsoft sentinel Documentation
“Playbooks with this trigger do not support alert grouping, meaning they will receive only the first alert sent with each incident. ”

Why the incident trigger do not support alert grouping and why they will only receive the first alert. Thank you so much, I just can’t get my head around with this concept.
Cheers

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,026 questions
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,251 Reputation points Microsoft Employee
    2021-09-13T05:02:09.86+00:00

    @Minghui Zou Thanks for reaching out.

    This is more of a known limitation and Product group might make some changes in future.
    You can always always use the alert trigger to group the alerts and perform automation.

    Do you have any specific scenario in mind which is causing the road blocker ?

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful