Question on the new Incident Settings page in Analytics rule creation

%3CLINGO-SUB%20id%3D%22lingo-sub-1182176%22%20slang%3D%22en-US%22%3EQuestion%20on%20the%20new%20Incident%20Settings%20page%20in%20Analytics%20rule%20creation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1182176%22%20slang%3D%22en-US%22%3E%3CP%3ELooking%20at%20this%20new%20page%20I%20see%20there%20is%20a%20setting%20where%20you%20can%20enable%20or%20disable%20the%20creation%20of%20Incidents%20from%20this%20analytics%20rule.%26nbsp%3B%20Why%20would%20you%20do%20that%3F%26nbsp%3B%20Isn't%20the%20purpose%20of%20an%20alert%20to%20create%20an%20Incident%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20something%20along%20the%20lines%20that%20you%20may%20not%20care%20about%20the%20actual%20alert%20(like%20when%20a%20new%20account%20is%20created)%20but%20you%20want%20it%20out%20there%20for%20Machine%20Learning%20to%20use%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20a%20side%20note%2C%20it%20kind%20of%20sucks%20that%20I%20had%20to%20stumble%20on%20this.%26nbsp%3B%20I%20have%20not%20found%20any%20sort%20of%20announcement%20of%20this%20new%20functionality%20anywhere.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1183908%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20on%20the%20new%20Incident%20Settings%20page%20in%20Analytics%20rule%20creation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1183908%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3BI%20have%20the%20opposite%20problem%20that%20a%20rule%20(a%20default%20one%20it%20seems)%20does%20not%20produce%20accurate%20results%20and%20thus%20generates%20alot%20of%20'false%20positive%20incidents'%20that%20skew%20my%20newly%20create%20PowerBi%20inc%20dashboard%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAbout%20the%20alerts%20-%20incident%20relationship..%20I%20had%20some%20past%20experience%20on%20Arcsight%2FLogrhythm%20where%20we%20wanted%20to%20generate%20alerts%20but%20not%20immediately%20report%20them%20to%20analysts%20via%20tickets%20but%20rather%20use%20alerts%20in%20other%20analytics%20rules.%20if%20that%20makes%20sense.%20Or%20have%20an%20alert%20rule%20in%20'test%2Fdev'%20mode%20without%20generating%20incidents.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20agree%20on%20the%20notification%20part.%20It%20would%20be%20great%20to%20have%20some%20'release%20notes'%20banner%2Fbutton%2Fpage%20on%20the%20portal%20to%20skim%20through%20new%20changes.%20All%20(cloud)%20products%20change%20so%20fast%20its%20really%20hard%20to%20keep%20up%20with%20all%20'unannounced%20changes'.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Super Contributor

Looking at this new page I see there is a setting where you can enable or disable the creation of Incidents from this analytics rule.  Why would you do that?  Isn't the purpose of an alert to create an Incident?

 

Is this something along the lines that you may not care about the actual alert (like when a new account is created) but you want it out there for Machine Learning to use?

 

On a side note, it kind of sucks that I had to stumble on this.  I have not found any sort of announcement of this new functionality anywhere.

1 Reply
Highlighted

@Gary Bushey I have the opposite problem that a rule (a default one it seems) does not produce accurate results and thus generates alot of 'false positive incidents' that skew my newly create PowerBi inc dashboard :) 

 

About the alerts - incident relationship.. I had some past experience on Arcsight/Logrhythm where we wanted to generate alerts but not immediately report them to analysts via tickets but rather use alerts in other analytics rules. if that makes sense. Or have an alert rule in 'test/dev' mode without generating incidents.

 

I agree on the notification part. It would be great to have some 'release notes' banner/button/page on the portal to skim through new changes. All (cloud) products change so fast its really hard to keep up with all 'unannounced changes'.