Elastic medium stable kql
Microsoft Defender XDR Incident External Alerts
Generates a detection alert for each Microsoft Defender XDR incident written to the configured indices. Microsoft Defender emits multiple update events for the same incident as its member alerts and status evolve, all sharing a stable incident identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained per Defender incident rather than a new alert per update. Enabling this rule allows you to immediately begin investigating Microsoft Defender XDR incidents in the app.
Detection Logic
event.kind: alert and data_stream.dataset: m365_defender.incident Field Validations
Loading…
Comments (0)
Loading comments...