sentinel incident and alert

Minghui Zou 186 Reputation points

hi community nice folks

I am new to sentinel, so I have a quick questions, is it possible to have zero alert and and many incidents? cuz to my understanding incidents are made up of one or many alerts. but today at my portal I see zero alert and many incidents


Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,020 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 35,616 Reputation points Microsoft Employee

    Though incidents are usually generated from alerts, it is possible to generate incidents without any alerts. An incident can be generated without an alert, but an alert cannot be generated without an incident. There is a script here that shows how to create an incident without an alert.

    One reason to create an incident without an alert would be to store an incident from an external source that hasn't been integrated with Azure Sentinel yet. (There is a blog post here that discusses this concept in detail.)

    0 comments No comments

0 additional answers

Sort by: Most helpful