Define filter and aggregation criteria
Define filter and aggregation conditions to control which Microsoft Defender incidents generate new security incidents and whether incoming incidents should be merged into existing ones. These conditions ensure accurate incident grouping and prevent unnecessary duplication.
Before you begin
Role required: sn_si.admin, sn_si.ingestion_profile_admin
About this task
Procedure
What to do next
Set a schedule to retrieve the incident data and ingested incidents that match the criteria in the profile. For more information, see Schedule incident retrieval.