Forum Discussion
NCreminder
Jul 19, 2022Copper Contributor
defender incidents are automatically re-opening
Hi, Recently, I've observed that defender incidents are automatically changing the status from Resolved to Active. When I checked the comments on the incident, I can clearly see that automation ...
HeikeRitter
Microsoft
Jul 22, 2022Hi,
can you explain more about it please. Who is first resolving the incident? Manually done before the automation starts its investigation?
can you explain more about it please. Who is first resolving the incident? Manually done before the automation starts its investigation?
NCreminder
Aug 04, 2022Copper Contributor
First, I closed the incident manually, and then the incident is automatically re-opened by automation. (please note that in this whole process of closing and re-opening incidents, I don't see the AIR(Automation Investigation & Remediation) kicked in and doing something to the incident - Basically, there is no sign of Automation investigation triggered in the incident )
- Gerson LevitzAug 05, 2022Iron ContributorWhen the Incident is re-opened are all of the alerts still closed / resolved?
- NCreminderAug 05, 2022Copper Contributorthose are marked as new after they are re-opened
- Gerson LevitzAug 05, 2022Iron ContributorJust to clarify are all the alerts in the Incident marked as "new" after the incident is re-opened?
Are there any new alerts that have been added / updated the same time the incident was re-opened?