Automate alert updates and closure based on SIR incident status
-
- UpdatedFeb 1, 2024
- 2 minutes to read
- Washington DC
- Security Incident Response integrations
The Microsoft Graph Security API alert ingestion integration has a bi-directional interface that allows for both alerts to create security incidents, as well as an ability to update the alerts once the security incident is created and/or closed with relevant incident details such as SIR incident number, assignment group, SIR incident URL, and so on. This section is the final portion of the profile configuration set-up that provides optional capabilities to update the alerts.
Before you begin
Procedure