Schedule the Microsoft Azure Sentinel incident retrieval
-
- UpdatedJan 30, 2025
- 2 minutes to read
- Yokohama
- Security Incident Response integrations
Set a schedule to retrieve the incident data and to ingest the Microsoft Azure Sentinel incidents that match the criteria in the profile.
Before you begin
Role required: sn_sni.admin
About this task
To enable automated incident ingestion, you must configure the scheduling and incident retrieval before you activate the profile. To define a specific date and time for the initial ingestion, enable set incident ingestion time. Subsequent ingestion is based on the polling interval period.
The polling interval is configured for each profile individually. The different polling intervals may impact the performance of the Microsoft Azure Sentinel incident integration. When scheduling, plan to balance the system load against the urgency of an incident. A one-minute default value is set for all profiles. You can modify this setting based on the urgency of the incident and the anticipated load on your system.
Any alerts that gets added to the incident in a particular polling interval there will be a process executed and then appended to the Azure Sentinel alerts related lists and worknote is also posted.
Procedure