You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@@ -193,12 +197,22 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
193
197
194
198
1.**Re-open closed matching incidents**: If an incident has been resolved and closed, and later on another alert is generated that should belong to that incident, set this setting to **Enabled** if you want the closed incident re-opened, and leave as **Disabled** if you want the alert to create a new incident.
195
199
200
+
This option is not available when Microsoft Sentinel is onboarded to the Microsoft Defender portal.
201
+
202
+
> [!IMPORTANT]
203
+
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, the **alert grouping** settings take effect only at the moment that the incident is created.
204
+
>
205
+
> Because the Defender portal's correlation engine is responsible for alert correlation in this scenario, it accepts these settings as initial instructions, but it also might make decisions about alert correlation that don't take these settings into account.
206
+
>
207
+
> Therefore, the way alerts are grouped into incidents might often be different than you would expect based on these settings.
208
+
196
209
> [!NOTE]
197
210
>
198
211
> **Up to 150 alerts** can be grouped into a single incident.
199
212
> - The incident will only be created after all the alerts have been generated. All of the alerts will be added to the incident immediately upon its creation.
200
213
>
201
214
> - If more than 150 alerts are generated by a rule that groups them into a single incident, a new incident will be generated with the same incident details as the original, and the excess alerts will be grouped into the new incident.
0 commit comments