elastic
medium
kql
Microsoft Defender XDR Incident External Alerts
Generates a detection alert for each Microsoft Defender XDR incident written to the configured indices. Microsoft
Defender emits multiple update events for the same incident as its member alerts and status evolve, all sharing a stable
incident identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained
per Defender incident rather than a new alert per update. Enabling this rule allows you to immediately begin
investigating Microsoft Defender XDR