Forum Discussion

wootts's avatar
wootts
Iron Contributor
Oct 30, 2020

Defender ATP into Sentinel and then SNOW

Hi all 

I am wanting to move Defender ATP (and other microsoft stack) alerts / incidents into Sentinel (which is easily achieved) and from here move them out into SNOW - what is the current thinking about how to aggregate the incidents as in MTP they have a start time and then an updated time (multiple alerts can become one incident by example).  

4 Replies

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    Adding to what Gary already said.
    We do the same, but with JIRA. It is possible; but not for incidents.
    Currently Sentinel will only ingest alerts, not incidents.

    It works through Seninel, but it's not ideal
  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    wootts If I am understanding what you are trying to do correctly, you cannot do it. Alerts coming from other Azure security platforms, like Defender ATP, cannot be combined into a single incident.  That functionality is only for Scheduled rules.