Elastic medium stable kql
Microsoft Defender XDR Alert External Alerts
Generates a detection alert for each Microsoft Defender XDR alert written to the configured indices. Microsoft Defender emits multiple update events for the same alert over its lifecycle, all sharing a stable alert identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained per Defender alert rather than a new alert per update. Enabling this rule allows you to immediately begin investigating Microsoft Defender XDR alerts in the app.
Detection Logic
event.kind: alert and data_stream.dataset: m365_defender.alert Field Validations
Loading…
Comments (0)
Loading comments...