Defining filter and aggregation criteria
You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
Microsoft has extended the deprecation of the Azure Sentinel experience in the Azure portal from March 2026 to March 2027.
If you are currently using the Azure Sentinel integration with Security Incident Response (SIR), we strongly recommend migrating to the new Defender portal integration as soon as possible. The Defender integration includes a built-in migration utility that automatically converts your existing Sentinel profiles into Defender profiles, while ensuring continuity of incidents created through Sentinel after the transition. For more information, see Microsoft Sentinel to Defender Migration Guide.
Set the filtering conditions for security incidents
Set the filtering conditions so that security incidents are created only when the filtering conditions match.
Antes de Iniciar
Role required: sn_si.ingestion_profile_admin
Por Que e Quando Desempenhar Esta Tarefa
This type of filtering helps you to isolate security incidents and limits the number of security incidents that you create. If you set additional filtering criteria, only the required incidents are ingested without having to change the query or the triggered incident configuration.
Procedimento
Define aggregation conditions
Define additional incident aggregation criteria that aggregates an incoming incident to an existing SIR security incident instead of creating similar, potentially duplicate incidents. When you use field matching value criteria for each profile, this additional aggregation can reduce the number of active, overlapping security incidents by placing all related incidents data on a single security incident.
Antes de Iniciar
Role required: sn_si.ingestion_profile_admin
Por Que e Quando Desempenhar Esta Tarefa
All the aggregated incidents on a security incident are displayed on the Azure Sentinel Aggregated Incidents related list. This list details the associated timestamps and aggregated field values. This information helps you understand why incidents are added to the existing security incidents.
Procedimento
O que Fazer Depois
Set a schedule to retrieve the incident data and ingested incidents that match the criteria in the profile.