Schedule the DLP IR Microsoft incident retrieval
Set a schedule to retrieve the incident data and ingest Microsoft DLP IR incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Microsoft.
Avant de commencer
Role required: sn_dlir.admin(Create, edit, and delete)
sn_dlir.analyst - View (read-only)
Pourquoi et quand exécuter cette tâche
You can plan how often you’ll poll for future incidents that match the incident profile configuration. To enable automated incident ingestion, you must configure the scheduling and incident retrieval before you activate the profile. The profile can be configured to do one-time retrieval using the One-Time Retrieval check box. The historical date can be up to the last three months from the current date.
The polling interval is configured for each profile individually. The different polling intervals may impact the performance of the Microsoft DLP IR incident integration. When scheduling, plan to balance the system load against the urgency of an incident.