Skip to content

Commit b972a11

Browse files
authored
Added another disclaimer
1 parent 2aae0af commit b972a11

File tree

1 file changed

+8
-6
lines changed

1 file changed

+8
-6
lines changed

articles/sentinel/create-analytics-rules.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -197,12 +197,14 @@ In the **Incident settings** tab, choose whether Microsoft Sentinel turns alerts
197197

198198
1. **Re-open closed matching incidents**: If an incident has been resolved and closed, and later on another alert is generated that should belong to that incident, set this setting to **Enabled** if you want the closed incident re-opened, and leave as **Disabled** if you want the alert to create a new incident.
199199

200-
> [!IMPORTANT]
201-
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, the **alert grouping** settings take effect only at the moment that the incident is created.
202-
>
203-
> Because the Defender portal's correlation engine is responsible for alert correlation in this scenario, it accepts these settings as initial instructions, but it also might make decisions about alert correlation that don't take these settings into account.
204-
>
205-
> Therefore, the way alerts are grouped into incidents might often be different than you would expect based on these settings.
200+
This option is not available when Microsoft Sentinel is onboarded to the Microsoft Defender portal.
201+
202+
> [!IMPORTANT]
203+
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, the **alert grouping** settings take effect only at the moment that the incident is created.
204+
>
205+
> Because the Defender portal's correlation engine is responsible for alert correlation in this scenario, it accepts these settings as initial instructions, but it also might make decisions about alert correlation that don't take these settings into account.
206+
>
207+
> Therefore, the way alerts are grouped into incidents might often be different than you would expect based on these settings.
206208
207209
> [!NOTE]
208210
>

0 commit comments

Comments
 (0)