Sentinel Analytics Rule not creating incident

Conor Bateman (Alcom IT) 0 Reputation points
2025-02-26T14:51:55.7166667+00:00

I have worked with Microsoft Support and created an Analytics rule to raise an incident when 5 or more failed login attempts are detected, followed by a success.

This worked originally but has now stopped working.

Nothing has changed. I cannot figure out why this could have stopped working.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,241 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,876 Reputation points Microsoft Employee
    2025-02-27T12:45:43.73+00:00

    Agreed. We will need more information to assist. I recommend copying the rule query into Log Analytics to run or use the test option 'runs' on the rule. When testing the query independently, try commenting out the threshold, any parameters, and possibly the project statement. Look to verify that the underlying data is present. Verify that the lookback timespan is sufficient.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.