Forum Discussion
Dean_Gross
May 26, 2022Silver Contributor
Investigation Status - Unsupported Alert Type from MDCA
What does in mean when an alert from MDCA shows up as an Unsupported Alert Type
ChrisWebbTech yes I have tried switch monitor hookup and even tried only having one monitor hooked up. The only thing that seems to work is reducing resolution
6 Replies
Sort By
- HeikeRitter
Microsoft
Hi Dean, this means that our AutoIR can't pick-up the alert to do an automated investigation. For some alerts we don't have a playbook (yet)- Jason0903Copper Contributor
Hi, is there any playbook for this yet?
What does it mean when an alert from MDE shows up as an Unsupported Alert Type - john1263Copper Contributor
HeikeRitter Hi Ms Ritter
Silly question.
Does that mean the AutoIR capability works in general but just doesnt work for any IPs indicated in IOCs?
- HeikeRitter
Microsoft
There is no such things as silly questions! 🙂
No, it means it can't handle certain alert TYPES, but it doesn't mean that it can't investigate and remediate IP related alerts.
- Dean_GrossSilver Contributorthanks, it would be helpful if that was documented somewhere.
- HeikeRitter
Microsoft
Thanks Dean; I've requested that update to the doc page and it will be added. Thanks again!