SOLVED

Where is the "Exclude by alert name"?

%3CLINGO-SUB%20id%3D%22lingo-sub-1112985%22%20slang%3D%22en-US%22%3EWhere%20is%20the%20%22Exclude%20by%20alert%20name%22%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1112985%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20looking%20at%20the%20built-in%20out%20of%20box%20%3CSTRONG%3ECreate%20incidents%20based%20on%20%3CMICROSOFT%20security%3D%22%22%20service%3D%22%22%3E%20alerts%3C%2FMICROSOFT%3E%3C%2FSTRONG%3E%20rules.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20you%20click%20on%20the%20rule%20from%20the%20Analytics%20page%20you%20see%20the%20rule%20summary%20page%20(see%20attachment%20%231)%20there%20you'll%20see%20a%20field%20for%20%22%3CSPAN%3EExclude%20by%20alert%20name%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWhen%20you%20attempt%20to%20edit%20this%20same%20rule%2C%20there%20is%20no%20field%20for%26nbsp%3B%22Exclude%20by%20alert%20name%22%20(see%20attachment%20%232)%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAm%20I%20missing%20something%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1113177%22%20slang%3D%22en-US%22%3ERe%3A%20Where%20is%20the%20%22Exclude%20by%20alert%20name%22%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1113177%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F370232%22%20target%3D%22_blank%22%3E%40ehloworldio%3C%2FA%3E%26nbsp%3BIf%20I%20had%20to%20guess%20it%20is%20some%20old%20hold-over%20in%20the%20UI.%26nbsp%3B%20I%20looked%20at%20the%20REST%20API%20for%20those%20types%20of%20entries%20and%20I%20did%20not%20see%20a%20field%20that%20would%20hold%20that%20information.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I'm looking at the built-in out of box Create incidents based on <Microsoft security service> alerts rules.

 

When you click on the rule from the Analytics page you see the rule summary page (see attachment #1) there you'll see a field for "Exclude by alert name"

 

When you attempt to edit this same rule, there is no field for "Exclude by alert name" (see attachment #2)

 

Am I missing something?

1 Reply
best response confirmed by ehloworldio (Occasional Contributor)
Solution

Just saw this, thanks MS for adding it.

 

clipboard_image_0.png