Elastic medium stable kql

Microsoft Defender XDR Alert External Alerts

Generates a detection alert for each Microsoft Defender XDR alert written to the configured indices. Microsoft Defender emits multiple update events for the same alert over its lifecycle, all sharing a stable alert identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained per Defender alert rather than a new alert per update. Enabling this rule allows you to immediately begin investigating Microsoft Defender XDR alerts in the app.

View Source

Detection Logic

event.kind: alert and data_stream.dataset: m365_defender.alert

Field Validations

Loading…

Comments (0)

Loading comments...