azure sentinel incident status values - modify

nigel sykes 21 Reputation points
2022-02-25T10:18:10.813+00:00

Hi

I wish to add an additional sentinel incident status value . Is this possible and how do you modify the list of status values

Regards

Nigel

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,065 questions
0 comments No comments
{count} votes

2 additional answers

Sort by: Most helpful
  1. nigel sykes 21 Reputation points
    2022-02-25T15:20:20.457+00:00

    Will this be an enhancement going forward. and if yes any timescales ?

    It is quite critical to MSSP operations and creating playbook triggers .

    0 comments No comments

  2. Andrew Blumhardt 9,776 Reputation points Microsoft Employee
    2022-02-25T17:30:11.64+00:00

    I am sure the request has been considered but I have no info on development or timelines. I am not aware of this being on any of the early previews. You might get more info from your Microsoft support contacts if available. Not something that could be discussed on an open forum.

    You might consider tagging or some other tracking mechanism to meet your needs. Maybe the new ingestion-time filtering. https://learn.microsoft.com/en-us/azure/azure-monitor/logs/ingestion-time-transformations

    0 comments No comments