Oct 26 2020 07:49 PM
I am using this query for security incident but getting all incident that having in Sentinel in that query. How to separate and not having duplication on the incident while generate pie charts.
Securityincident
Oct 27 2020 04:42 AM
@Vshah335 Try something like:
Oct 27 2020 07:28 AM
Thanks @Gary Bushey for quick reply.
My question is : Ex- we have two X and Y different tenants in same workspace.
ex - if i assigned to my self - New - viral
- Assigned to- viral
- close - viral
So i just want to monitored Y tenant security incident only on top of that when i try run query against it shows results same incident again and again. It's counts 3 incident on results instead of one incident. (Number went high while i generate pie chart )
Is there any why to count main incident which genreated first shows in results ?
Thanks for your response.
Oct 27 2020 09:04 AM
@Vshah335 This should do it