This is not currently possible.
azure sentinel incident status values - modify
Hi
I wish to add an additional sentinel incident status value . Is this possible and how do you modify the list of status values
Regards
Nigel
-
Andrew Blumhardt 9,776 Reputation points Microsoft Employee
2022-02-25T14:41:23.21+00:00
2 additional answers
Sort by: Most helpful
-
nigel sykes 21 Reputation points
2022-02-25T15:20:20.457+00:00 Will this be an enhancement going forward. and if yes any timescales ?
It is quite critical to MSSP operations and creating playbook triggers .
-
Andrew Blumhardt 9,776 Reputation points Microsoft Employee
2022-02-25T17:30:11.64+00:00 I am sure the request has been considered but I have no info on development or timelines. I am not aware of this being on any of the early previews. You might get more info from your Microsoft support contacts if available. Not something that could be discussed on an open forum.
You might consider tagging or some other tracking mechanism to meet your needs. Maybe the new ingestion-time filtering. https://learn.microsoft.com/en-us/azure/azure-monitor/logs/ingestion-time-transformations