Create Incident for XDR Alerts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This Query creates an incident based on Trend Vision One Workbench Alerts and maps the impacted entities for Microsoft Sentinel usage.

Attribute Value
Type Analytic Rule
Solution Trend Micro Vision One
ID 0febd8cc-1b8d-45ed-87b3-e1e8a57d14cd
Severity High
Status Available
Kind Scheduled
Required Connectors TrendMicroXDR
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
TrendMicro_XDR_WORKBENCH_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Trend Micro Vision One