Forum Discussion
Webinar: Sentinel IT/OT Threat Monitoring
8 Replies
- Dean_GrossSilver Contributor
how come the vendors actions created multiple incidents? i thought that sentinel would be correlating all of the alerts into one incidentamitcohen
- amitcohen
Microsoft
Hi Dean_Gross ,
It is possible to define in Sentinel whether you want to create a separate incident for each Defender for IoT alert or whether you want to group a few alerts into the same incident.
- Dean_GrossSilver Contributor
amitcohen I understand that option exists, I just don't understand why it would be necessary. All of the alerts shown in the demo are obviously part of the same incident, so how come they were not correlated automatically? This is supposed to be one of the key benefits of Sentinel
- CindySvB2022Copper ContributorHello, has this webinar been recorded by any chance?
- amitcohen
Microsoft
Hi CindySvB2022,
Yes. You can find the recording here:
https://www.youtube.com/watch?v=nbCg8jlR1Gk- CindySvB2022Copper ContributorThanks!
- Anonymous
amitcohen Is the webinar also about the way D4IOT alert and device information is made available to Sentinel when using the on-premise management console? As far as I can see, the current documentation is always assuming that a cloud connected sensor is used.
- amitcohen
Microsoft
Deleted Defender for IoT integration to Sentinel can be done in two ways; either using cloud-connected sensors or non-cloud-connected sensors.
In the webinar, we will focus on the new integration that requires a cloud-connected sensor as a prerequisite, since most of the advanced features of a unified OT/IT SOC are available for that kind of integration.