Discussion about this post

User's avatar
Jeremy's avatar

In Sentinel, I'm able to decide which connectors to pull in events from (ie, not to pull in DLP incidents). I don't seem to have that same ability once I'm connected in the Unified Experience.

We have a separate team that generates hundreds of alerts per day for DLP policies that randomly get correlated with items we're looking at as Security Operations... and when we close our investigation, we close their alerts and mess up their stats and workflow.

If only we had a way to filter these out so they didn't get correlated. Similar to the toggle button we were given for IRM...

Expand full comment
3 more comments...

No posts