A Microsoft Sentinel analytics rule is enabled but never fires for lock-lab activity that should match. What should the Azure security engineer check next?
Select an answer to reveal the explanation.
Short Explanation
An enabled rule with an empty pipe never rings. Confirm the required connectors and data types are actually landing in the workspace—no ingest, no incidents.
Full Explanation
Analytics rules depend on live data from their required connectors and tables. If connectors or DCRs are not ingesting, an enabled rule will not create incidents. Checking connector health and data types is the enable-and-configure fix; Security Copilot rewrites, Informational severity alone, or Azure Policy gallery myths are not the primary diagnosis.