Skip to content

Commit 25c70a9

Browse files
committed
What's new
1 parent 44f7fbf commit 25c70a9

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

articles/sentinel/whats-new.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ See these [important announcements](#announcements) about recent changes to feat
1818

1919
[!INCLUDE [reference-to-feature-availability](includes/reference-to-feature-availability.md)]
2020

21+
## February 2023
22+
23+
- [New behavior for alert grouping in analytics rules](#new-behavior-for-alert-grouping-in-analytics-rules) (in [Announcements](#announcements) section below)
24+
2125
## January 2023
2226

2327
- [New incident investigation experience (Preview)](#new-incident-investigation-experience-preview)
@@ -126,7 +130,7 @@ A [new version of the Microsoft Sentinel Logstash plugin](connect-logstash-data-
126130

127131
### New behavior for alert grouping in analytics rules
128132

129-
As of **February 2, 2023**, Microsoft Sentinel is changing the way that incidents are created from analytics rules with certain event and alert grouping settings, and also the way that such incidents are updated by automation rules. This change is being made in order to produce incidents with more complete information and to simplify automation triggered by the creating and updating of incidents.
133+
Starting **February 6, 2023** and continuing through the end of February, Microsoft Sentinel is rolling out a change in the way that incidents are created from analytics rules with certain event and alert grouping settings, and also the way that such incidents are updated by automation rules. This change is being made in order to produce incidents with more complete information and to simplify automation triggered by the creating and updating of incidents.
130134

131135
The affected analytics rules are those with both of the following two settings:
132136
- **Event grouping** is set to **Trigger an alert for each event** (sometimes referred to as "alert per row" or "alert per result").

0 commit comments

Comments
 (0)