One Microsoft Sentinel analytics rule created two hundred lock-lab incidents overnight. What should the Azure security engineer do?
Select an answer to reveal the explanation.
Short Explanation
Two hundred incidents by sunrise means the rule’s too chatty. Dial threshold, lookback, entity mapping, or grouping—or park the rule—before you try inventing a new query language.
Full Explanation
Noisy analytics rules are handled by enable-and-configure tuning. Adjust threshold, lookback period, entity mapping, and incident grouping, or disable the rule until it is fixed. Rewriting an entire Content Hub catalog is unnecessary noise control. Relying on UEBA notebooks or outsourcing configuration to Security Copilot is outside the intended AZ-500 skill for this item.