Chapter 9: Incident Management
In Chapter 7, Creating Analytic Rules, you learned that rules in analytics create incidents. These incidents can represent potential issues with your environment and need to be looked at to determine whether they are indeed an issue. Are they false positives, irrelevant to your environment, or actual issues? The way to determine this is through incident management.
There are no hard-and-fast rules for incident management, other than to look at the incidents and determine whether they are actual issues. There are various ways to do this, and this chapter will look at the options Microsoft Sentinel provides to perform these investigations, including a graphical representation of the incident, viewing the full details of the incident, and running other queries to obtain more information.
In this chapter, we will cover the following topics:
- Using the Microsoft Sentinel Incidents page
- Exploring the full details page
- Investigating an incident...