Skip to content

Commit 333a30f

Browse files
authored
Merge pull request #5271 from mberdugo/ActivityLogMerge
activity log merge improvements in preview - Naomi Christis
2 parents 8a2eb86 + 3f4cbee commit 333a30f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-xdr/alerts-incidents-correlation.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ The contents of the incidents are handled in the following ways:
7777
- A **`Redirected`** tag is added to the source incident.
7878
- Entities (assets etc.) follow the alerts they're linked to.
7979
- Analytics rules recorded as involved in the creation of the source incident are added to the rules recorded in the target incident.
80-
- Currently, comments and activity log entries in the source incident are *not* moved to the target incident.<br>To see the source incident's comments and activity history, open the incident in Microsoft Sentinel in the Azure portal. The activity history includes the closing of the incident and the adding and removal of alerts, tags, and other items related to the incident merge. These activities are attributed to the identity *Microsoft Defender XDR - alert correlation*.
80+
- Currently, migration of comments and audits of activity log entries is in *preview*.<br>To see the source incident's comments and activity history if you don't have access to the preview, open the incident in Microsoft Sentinel in the Azure portal. The activity history includes the closing of the incident and the adding and removal of alerts, tags, and other items related to the incident merge. These activities are attributed to the identity *Microsoft Defender XDR - alert correlation*.
8181

8282
### When incidents aren't merged
8383

0 commit comments

Comments
 (0)