Forum Discussion

SocInABox's avatar
SocInABox
Iron Contributor
Apr 03, 2025

How to use KQL to associate alerts with incidents?

There is no method I'm aware of to use KQL to query from an alertID to an incident or vice versa. Please provide kql examples for querying between XDR incidents and alerts. These queries should be ...

Resources