Set a schedule to retrieve the incident data and to ingest the Microsoft Azure Sentinel incidents that match the criteria in the profile.

Before you begin

Role required: sn_sni.admin

About this task

You can plan how often you want to poll for future Microsoft Azure Sentinel incidents that match the incident profile configuration.

To enable automated incident ingestion, you must configure the scheduling and incident retrieval before you activate the profile. To define a specific date and time for the initial ingestion, enable set incident ingestion time. Subsequent ingestion is based on the polling interval period.

The polling interval is configured for each profile individually. The different polling intervals may impact the performance of the Microsoft Azure Sentinel incident integration. When scheduling, plan to balance the system load against the urgency of an incident. A one-minute default value is set for all profiles. You can modify this setting based on the urgency of the incident and the anticipated load on your system.

Any alerts that gets added to the incident in a particular polling interval there will be a process executed and then appended to the Azure Sentinel alerts related lists and worknote is also posted.

Procedure

  1. On the scheduling form, fill in the fields.

    Configure the schedule to define how and when you pull incidents from the Microsoft Azure tenant.

    The scheduling page enables you to define how and when incidents are pulled from the Microsoft Azure tenant.

  2. To navigate to the Additional Options page, click Continue.