Elastic medium stable kql

Microsoft Defender XDR Incident External Alerts

Generates a detection alert for each Microsoft Defender XDR incident written to the configured indices. Microsoft Defender emits multiple update events for the same incident as its member alerts and status evolve, all sharing a stable incident identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained per Defender incident rather than a new alert per update. Enabling this rule allows you to immediately begin investigating Microsoft Defender XDR incidents in the app.

View Source

Detection Logic

event.kind: alert and data_stream.dataset: m365_defender.incident

Field Validations

Loading…

Comments (0)

Loading comments...