Skip to content

Commit 38e6764

Browse files
committed
Added disclaimer
1 parent ff268cf commit 38e6764

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

articles/sentinel/create-incidents-from-alerts.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,16 +4,23 @@ description: Learn how to create incidents from alerts in Microsoft Sentinel.
44
author: yelevin
55
ms.topic: how-to
66
ms.custom: mvc
7-
ms.date: 11/09/2021
7+
ms.date: 05/29/2024
88
ms.author: yelevin
99
---
1010

1111
# Automatically create incidents from Microsoft security alerts
1212

13-
Alerts triggered in Microsoft security solutions that are connected to Microsoft Sentinel, such as Microsoft Defender for Cloud Apps and Microsoft Defender for Identity, do not automatically create incidents in Microsoft Sentinel. By default, when you connect a Microsoft solution to Microsoft Sentinel, any alert generated in that service will be stored as raw data in Microsoft Sentinel, in the *SecurityAlert* table in your Microsoft Sentinel workspace. You can then use that data like any other raw data you ingest into Microsoft Sentinel.
13+
Alerts triggered in Microsoft security solutions that are connected to Microsoft Sentinel, such as Microsoft Defender for Cloud Apps and Microsoft Defender for Identity, do not automatically create incidents in Microsoft Sentinel. By default, when you connect a Microsoft solution to Microsoft Sentinel, any alert generated in that service will be ingested and stored in the *SecurityAlert* table in your Microsoft Sentinel workspace. You can then use that data like any other raw data you ingest into Microsoft Sentinel.
1414

1515
You can easily configure Microsoft Sentinel to automatically create incidents every time an alert is triggered in a connected Microsoft security solution, by following the instructions in this article.
1616

17+
> [!IMPORTANT]
18+
> **This article does not apply** if you have:
19+
> - Enabled [**Microsoft Defender XDR incident integration**](microsoft-365-defender-sentinel-integration.md), or
20+
> - Onboarded Microsoft Sentinel to the [**unified security operations platform**](microsoft-sentinel-defender-portal.md).
21+
>
22+
> In these scenarios, Microsoft Defender XDR creates incidents from alerts generated in Microsoft services.
23+
1724
## Prerequisites
1825

1926
Connect your security solution by installing the appropriate solution from the **Content Hub** in Microsoft Sentinel and setting up the data connector. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](sentinel-solutions-deploy.md) and [Microsoft Sentinel data connectors](connect-data-sources.md).

0 commit comments

Comments
 (0)