May 31 2022 01:06 PM
I would like to know how we can close multiple incidents in bulk using KQL query or any other tested option. Appreciate quick response.
May 31 2022 02:29 PM - edited Jan 24 2023 07:24 AM
See if the following helps: https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Update-BulkIncidents
Jun 01 2022 03:57 AM