Forum Discussion

jmn05's avatar
jmn05
Copper Contributor
Apr 15, 2024

New Sentinel Integration Causing a Single Large Incident

I migrated Sentinel to the new Defender XDR connector, giving it access to the SecurityAlerts and SecurityIncident table. Defender's entity matching is now creating one large incident of pretty much every Sentinel incident raised, meaning if we close it, it is just going to re-raise as the entity graph grows.

 

Has this happened to anyone else? How can we stop this from happening?

Resources