Skip to content

Commit 170766f

Browse files
committed
activity log merge improvements in preview - Naomi Christis
1 parent 57b4116 commit 170766f

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

defender-xdr/alerts-incidents-correlation.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,12 @@ The contents of the incidents are handled in the following ways:
7979
- Analytics rules recorded as involved in the creation of the source incident are added to the rules recorded in the target incident.
8080
- Currently, comments and activity log entries in the source incident are *not* moved to the target incident.<br>To see the source incident's comments and activity history, open the incident in Microsoft Sentinel in the Azure portal. The activity history includes the closing of the incident and the adding and removal of alerts, tags, and other items related to the incident merge. These activities are attributed to the identity *Microsoft Defender XDR - alert correlation*.
8181

82+
> [!NOTE]
83+
> The following enhancements to incident merging in the Activity log are in public preview:
84+
>
85+
> - Migration of audits and comments
86+
> - New audits
87+
8288
### When incidents aren't merged
8389

8490
Even when the correlation logic indicates that two incidents should be merged, Defender doesn't merge the incidents under the following circumstances:

0 commit comments

Comments
 (0)