0answers
QuestionOpen
Sentinel analytics rules firing too much — tuning approach?
My lab Sentinel is alert-storming. What's a sane order of operations to tune scheduled analytics rules?
Nina Petrov
Spaces
Microsoft security operations and threat response.
My lab Sentinel is alert-storming. What's a sane order of operations to tune scheduled analytics rules?
I can write basic queries but joining tables and building real detections still feels like guesswork. What made it click for you?