Investigating an incident
Remember how in Chapter 7, Creating Analytic Rules, you learned that the rules in analytics create incidents? Incidents are not worth anything if they just sit there without being investigated; after all, that is the reason they were created. An investigation is used to determine whether the incident is an issue. For example, an incident describing failed logins could be as simple as someone forgetting their password, or it could be someone trying to crack a password. You will not know which until an investigation is performed.
Now that you know how to look at an incident and retrieve all the information relating to it, it is time to see how to investigate an incident. The main way this is done in Microsoft Sentinel is via the graphical investigation page. This is a graphical interface that not only shows you the incident in question but can also be used to find related information.
When you are looking at an incident's details, at the bottom of...