Skip to content

Commit 6c93799

Browse files
committed
Removed references to features not yet released
1 parent 9944e0d commit 6c93799

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-xdr/alerts-incidents-correlation.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ When two or more incidents are merged, a new incident is *not* created to absorb
6262

6363
#### Merge direction
6464

65-
The direction of the incident merge refers to which incident is the source and which is the target. This direction is determined by Microsoft Defender, based on its own internal logic, with the goal of maximizing information retention and access. The user doesn't have any input into this decision, even when merging incidents manually.
65+
The direction of the incident merge refers to which incident is the source and which is the target. This direction is determined by Microsoft Defender, based on its own internal logic, with the goal of maximizing information retention and access. The user doesn't have any input into this decision.
6666

6767
#### Incident contents
6868

@@ -73,7 +73,7 @@ The contents of the incidents are handled in the following ways:
7373
- A **`Redirected`** tag is added to the source incident.
7474
- Entities (assets etc.) follow the alerts they're linked to.
7575
- Analytics rules recorded as involved in the creation of the source incident are added to the rules recorded in the target incident.
76-
- Comments and activity log entries in the source incident are moved to the target incident.
76+
- Currently, comments and activity log entries in the source incident are *not* moved to the target incident.
7777

7878
To see the source incident's comments and activity history, open the incident in Microsoft Sentinel in the Azure portal. The activity history includes the closing of the incident and the adding and removal of alerts, tags, and other items related to the incident merge. These activities are attributed to the identity *Microsoft Defender XDR - alert correlation*.
7979

0 commit comments

Comments
 (0)