Define filter and aggregation criteria
Define filter and aggregation conditions to control which Microsoft Defender incidents generate new security incidents and whether incoming incidents should be merged into existing ones. These conditions ensure accurate incident grouping and prevent unnecessary duplication.
Antes de Iniciar
Role required: sn_si.admin, sn_si.ingestion_profile_admin
Por Que e Quando Desempenhar Esta Tarefa
Filtering helps you isolate security incidents and limit the number of security incidents that you create. If you set additional filtering criteria, only the required incidents are ingested without having to change the query or the triggered incident configuration.
Aggregation Conditions define additional incident field criteria that enable an incoming incident to be appended to an open security incident instead of creating one.
Procedimento
O que Fazer Depois
Set a schedule to retrieve the incident data and ingested incidents that match the criteria in the profile. For more information, see Schedule incident retrieval.