<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Azure Sentinel Incident Aggregation Conditions in SecOps forum</title>
    <link>https://www.servicenow.com/community/secops-forum/azure-sentinel-incident-aggregation-conditions/m-p/3297798#M12980</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently setting up the integration with ServiceNow and Azure Sentinel. We created a profile for Azure Sentinel and wanted to ask if anyone has found a good or recommended solution on aggregating alerts (step 3 of profile set up). During the mapping we saw you can map multiple observables, but under the aggregating conditions list there is only one generic mention of "observable". We would like to add more matching fields if that's possible, preferably an observable that is the source IP.&amp;nbsp; Is there a way to edit this list of dropdowns? See screenshot for reference. Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2025 21:28:41 GMT</pubDate>
    <dc:creator>Mira_P</dc:creator>
    <dc:date>2025-06-23T21:28:41Z</dc:date>
    <item>
      <title>Azure Sentinel Incident Aggregation Conditions</title>
      <link>https://www.servicenow.com/community/secops-forum/azure-sentinel-incident-aggregation-conditions/m-p/3297798#M12980</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently setting up the integration with ServiceNow and Azure Sentinel. We created a profile for Azure Sentinel and wanted to ask if anyone has found a good or recommended solution on aggregating alerts (step 3 of profile set up). During the mapping we saw you can map multiple observables, but under the aggregating conditions list there is only one generic mention of "observable". We would like to add more matching fields if that's possible, preferably an observable that is the source IP.&amp;nbsp; Is there a way to edit this list of dropdowns? See screenshot for reference. Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 21:28:41 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/azure-sentinel-incident-aggregation-conditions/m-p/3297798#M12980</guid>
      <dc:creator>Mira_P</dc:creator>
      <dc:date>2025-06-23T21:28:41Z</dc:date>
    </item>
  </channel>
</rss>

