You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -193,12 +197,20 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
193
197
194
198
1.**Re-open closed matching incidents**: If an incident has been resolved and closed, and later on another alert is generated that should belong to that incident, set this setting to **Enabled** if you want the closed incident re-opened, and leave as **Disabled** if you want the alert to create a new incident.
195
199
200
+
> [!IMPORTANT]
201
+
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, the **alert grouping** settings take effect only at the moment that the incident is created.
202
+
>
203
+
> Because the Defender portal's correlation engine is responsible for alert correlation in this scenario, it accepts these settings as initial instructions, but it also might make decisions about alert correlation that don't take these settings into account.
204
+
>
205
+
> Therefore, the way alerts are grouped into incidents might often be different than you would expect based on these settings.
206
+
196
207
> [!NOTE]
197
208
>
198
209
> **Up to 150 alerts** can be grouped into a single incident.
199
210
> - The incident will only be created after all the alerts have been generated. All of the alerts will be added to the incident immediately upon its creation.
200
211
>
201
212
> - If more than 150 alerts are generated by a rule that groups them into a single incident, a new incident will be generated with the same incident details as the original, and the excess alerts will be grouped into the new incident.
0 commit comments