Skip to content

Commit 757f117

Browse files
committed
Fix
1 parent 277e931 commit 757f117

File tree

1 file changed

+0
-4
lines changed

1 file changed

+0
-4
lines changed

defender-xdr/alerts-incidents-correlation.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -78,10 +78,6 @@ Even when the correlation logic indicates that two incidents should be merged, D
7878
- Merging the two incidents would raise the number of entities in the merged incident above the allowed maximum of 50 entities per incident.
7979
- The two incidents contain devices in different [device groups](/defender-endpoint/machine-groups) as defined by the organization. <br>(This condition is not in effect by default; it must be enabled.)
8080

81-
## Manual correlation
82-
83-
While Microsoft Defender already uses advanced correlation mechanisms, you might want to decide differently whether a given alert belongs with a particular incident or not. In such a case, you can unlink an alert from one incident and link it to another. Every alert must belong to an incident, so you can either link the alert to another existing incident, or to a new incident that you create on the spot.
84-
8581
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
8682

8783
## Next steps

0 commit comments

Comments
 (0)