Skip to content

Commit 44f7fbf

Browse files
committed
Tweak
1 parent e4a9c24 commit 44f7fbf

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

articles/sentinel/detect-threats-custom.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -201,7 +201,11 @@ In the **Alert grouping** section, if you want a single incident to be generated
201201
- **Re-open closed matching incidents**: If an incident has been resolved and closed, and later on another alert is generated that should belong to that incident, set this setting to **Enabled** if you want the closed incident re-opened, and leave as **Disabled** if you want the alert to create a new incident.
202202
203203
> [!NOTE]
204-
> **Up to 150 alerts** can be grouped into a single incident. If more than 150 alerts are generated by a rule that groups them into a single incident, a new incident will be generated with the same incident details as the original, and the excess alerts will be grouped into the new incident.
204+
>
205+
> **Up to 150 alerts** can be grouped into a single incident.
206+
> - The incident will only be created after all the alerts have been generated. All of the alerts will be added to the incident immediately upon its creation.
207+
>
208+
> - If more than 150 alerts are generated by a rule that groups them into a single incident, a new incident will be generated with the same incident details as the original, and the excess alerts will be grouped into the new incident.
205209
206210
## Set automated responses and create the rule
207211

0 commit comments

Comments
 (0)