How can you create Azure Sentinel incidents based on the alerts from other Microsoft security services?

Experience Level: Junior
Tags: Azure CloudAzure Sentinel

Answer

Microsoft Incident Creation Rules can be used to achieve this.

  • Go to Azure Sentinel
  • Select Analytics
  • Select Create - Microsoft Incident Creation Rule
  • Set Name and Description of the rule
  • Select the source Microsoft security service
  • Include/Exclude specific alerts
  • Create the rule
Related Azure Cloud job interview questions

Comments

No Comments Yet.
Be the first to tell us what you think.
Azure Sentinel
Azure Sentinel

Are you learning Azure Cloud ? Try our test we designed to help you progress faster.

Test yourself