Forum Discussion

leo_szalk's avatar
leo_szalk
Copper Contributor
Jun 14, 2021

Azure Sentinel MSP - Non-Scheduled Alert Queries

What is the best approach to take to pull alerts/incidents from non-scheduled rule queries, such as Azure AD Identity Protection) into the MSSP Tenant?

Should it be done by using cross-workspace queries to create a custom query that pulls in events from the SecurityAlert table with the rule frequency being near real-time to mimic the events coming in from particular connectors? Or is there an easier, built-in method?

Resources