Discussion about this post

User's avatar
Jeremy's avatar

Are there details on how the incident merging works? We solved our problem with DLP events creating alerts/incidents... but we sync Sentinel incidents to our ticketing system.

With Defender XDR merging and closing incidents at will, this can cause confusion as we try to keep in sync.

Expand full comment
1 more comment...

No posts