Question Regarading Analytic rules

%3CLINGO-SUB%20id%3D%22lingo-sub-1535487%22%20slang%3D%22en-US%22%3EQuestion%20Regarading%20Analytic%20rules%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1535487%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20following%20Problem%2C%20i%20created%20an%20analytic%20rule%20which%20simply%20queries%20a%20log%20source%2C%26nbsp%3B%3C%2FP%3E%3CP%3Eusually%20this%20query%20rule%20does%20return%20multiple%20lines%20as%20a%20result.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20i%20simply%20want%20to%20have%20one%20I%3CSPAN%3Encident%20(Incident%20id)%26nbsp%3Bfor%20each%20of%20the%20results%20returned%20by%20the%20Query.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20Goal%20would%20that%20this%20Incident%20can%20be%20dispatched%20to%20different%20groups%20and%20investigated.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EUsually%20for%20of%20each%20line%20returned%20by%20the%20Analytic%20rule%20a%20different%20Team%20is%20responsible%2C%20%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ESo%2C%20I%20want%20to%20have%20Separate%20incidents%20for%20that.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20somebody%20explain%20me%20how%20to%20do%20so%2C%20I%20have%20meanwhile%20tried%20all%20the%20Possible%20settings%20in%20the%20Analytic%20Rule%20but%20so%20far%20did%20not%20found%20the%20right%20way%20to%20do%20so.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKR%3CBR%20%2F%3ESebastian%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1535514%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20Regarading%20Analytic%20rules%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1535514%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F425610%22%20target%3D%22_blank%22%3E%40smahrl%3C%2FA%3E%26nbsp%3BThis%20feature%20is%20in%20private%20preview%20and%20should%20be%20released%20soon%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1535531%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20Regarading%20Analytic%20rules%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1535531%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3Bthanks%20a%20lot%20for%20fast%20response%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EI%20thought%20i%20really%20missing%20something%20here.%3C%2FP%3E%3CP%3EHopefully%20that%20feature%20we%20be%20soon%20released%20to%20public.%3C%2FP%3E%3CP%3EWe%20do%20have%20very%20high%20demand%20on%20that.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKR%3CBR%20%2F%3ESebastian%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello

 

I have following Problem, i created an analytic rule which simply queries a log source, 

usually this query rule does return multiple lines as a result.

 

Now i simply want to have one Incident (Incident id) for each of the results returned by the Query.

The Goal would that this Incident can be dispatched to different groups and investigated. 

Usually for of each line returned by the Analytic rule a different Team is responsible,

So, I want to have Separate incidents for that.

 

Could somebody explain me how to do so, I have meanwhile tried all the Possible settings in the Analytic Rule but so far did not found the right way to do so.

 

KR
Sebastian

2 Replies

@smahrl This feature is in private preview and should be released soon

@Gary Bushey thanks a lot for fast response :)

I thought i really missing something here.

Hopefully that feature we be soon released to public.

We do have very high demand on that.

 

KR
Sebastian