Skip to content

Commit 8d64141

Browse files
authored
Merge pull request #1707 from cwatson-cat/patch-6
Defender incidents correlation -Update alerts-incidents-correlation.md
2 parents 699570b + 1196d1f commit 8d64141

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

defender-xdr/alerts-incidents-correlation.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.topic: conceptual
1717
search.appverid:
1818
- MOE150
1919
- MET150
20-
ms.date: 05/30/2024
20+
ms.date: 10/25/2024
2121
appliesto:
2222
- Microsoft Defender XDR
2323
- Microsoft Sentinel in the Microsoft Defender portal
@@ -103,7 +103,7 @@ Even when the correlation logic indicates that two incidents should be merged, D
103103

104104
- One of the incidents has a status of "Closed". Incidents that are resolved don't get reopened.
105105
- The two incidents eligible for merging are assigned to two different people.
106-
- Merging the two incidents would raise the number of entities in the merged incident above the maximum allowed.
106+
- Merging the two incidents would raise the number of entities in the merged incident above the maximum of 50 entities per incident allowed.
107107
- The two incidents contain devices in different [device groups](/defender-endpoint/machine-groups) as defined by the organization. <br>(This condition is not in effect by default; it must be enabled.)
108108

109109
### What happens when incidents are merged?

0 commit comments

Comments
 (0)