Share via

sentinel incident and alert

Minghui Zou 191 Reputation points
2021-09-13T09:47:17.603+00:00

hi community nice folks

I am new to sentinel, so I have a quick questions, is it possible to have zero alert and and many incidents? cuz to my understanding incidents are made up of one or many alerts. but today at my portal I see zero alert and many incidents

Cheers
zzzz

Microsoft Security | Microsoft Sentinel
0 comments No comments

Answer accepted by question author

  1. Marilee Turscak-MSFT 37,391 Reputation points Microsoft Employee Moderator
    2021-09-13T16:58:33.057+00:00

    Though incidents are usually generated from alerts, it is possible to generate incidents without any alerts. An incident can be generated without an alert, but an alert cannot be generated without an incident. There is a script here that shows how to create an incident without an alert.

    One reason to create an incident without an alert would be to store an incident from an external source that hasn't been integrated with Azure Sentinel yet. (There is a blog post here that discusses this concept in detail.)

    Was this answer helpful?

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.