Skip to content

Conversation

@Tanium-Nicole
Copy link
Collaborator

@Tanium-Nicole Tanium-Nicole commented Sep 10, 2025

What

  • Enhanced the incident that are created by this rule so the names are descriptive and specific rather than all having the same name
  • Fixed the issue where the alerts were being grouped

Why

  • A bunch of incidents with the same name isn't helpful and doesn't make it easy to navigate the list of incidents
  • Since the intention of this analytics rule is to be able to easily resolve Tanium Threat Response Alerts, then we should have a 1-to-1 relationship between Tanium THR Alerts and Sentinel Incidents

Does it work?

  • Yes, I published the rule to a workspace and then generated some incidents and the name displayed as expected
  • Yes, I published the rule to a workspace and then generated some incidents and ensured that the alerts were no longer being grouped
    See my attached screenshots
image image

How can someone else confirm these changes?

  1. Create the connection in the Connect Module to send Tanium THR alerts to an Azure Log Analytics Workspace
  2. Confirm that the data is being pushed to the workspace
  3. See the Tanium Wiki for how to build and publish the solution to the workspace
  4. Wait for a threat response alert to fire and then check the name and the source log analytics data to confirm they are no longer being grouped

@Tanium-Nicole
Copy link
Collaborator Author

Fixes [SENTINEL-184] & [SENTINEL-185]

Copy link
Collaborator

@caleb-clausen-t caleb-clausen-t left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Full review, looks great and ready for main merge!

@Tanium-Nicole Tanium-Nicole merged commit 4d58ad9 into versions/3.2.0 Sep 10, 2025
2 of 3 checks passed
@Tanium-Nicole Tanium-Nicole deleted the feat/analytics-rule/alert-names branch September 10, 2025 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants