sentinel incident and alert

Minghui Zou 186 Reputation points
2021-09-13T09:47:17.603+00:00

hi community nice folks

I am new to sentinel, so I have a quick questions, is it possible to have zero alert and and many incidents? cuz to my understanding incidents are made up of one or many alerts. but today at my portal I see zero alert and many incidents

Cheers
zzzz

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,178 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marilee Turscak-MSFT 36,926 Reputation points Microsoft Employee
    2021-09-13T16:58:33.057+00:00

    Though incidents are usually generated from alerts, it is possible to generate incidents without any alerts. An incident can be generated without an alert, but an alert cannot be generated without an incident. There is a script here that shows how to create an incident without an alert.

    One reason to create an incident without an alert would be to store an incident from an external source that hasn't been integrated with Azure Sentinel yet. (There is a blog post here that discusses this concept in detail.)

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.