Agreed. We will need more information to assist. I recommend copying the rule query into Log Analytics to run or use the test option 'runs' on the rule. When testing the query independently, try commenting out the threshold, any parameters, and possibly the project statement. Look to verify that the underlying data is present. Verify that the lookback timespan is sufficient.
Sentinel Analytics Rule not creating incident

Conor Bateman (Alcom IT)
0
Reputation points
I have worked with Microsoft Support and created an Analytics rule to raise an incident when 5 or more failed login attempts are detected, followed by a success.
This worked originally but has now stopped working.
Nothing has changed. I cannot figure out why this could have stopped working.
1 answer
Sort by: Most helpful
-
Andrew Blumhardt 9,876 Reputation points Microsoft Employee
2025-02-27T12:45:43.73+00:00