Alert XX was added to the incident by Microsoft Defender XDR - alert correlation
Hey, I am sending alarms/incidents from another SIEM to sentinel for centralization. The goal is that sentinel mirrors the alarms/incidents exactly.
The data is sent to a custom log table, in the log analytics workspace through an API call, and I have a NRT analytics rule that creates an alert pr event, and places it in an incident in sentinel.
But if any of the N next alarms being sent from my other SIEM has the same entities, XDR correlates them into one incident. This breaks my mirroring. I have tried to set an entity with a unique identifier to be created in each alert, but that doesn't work.
Any idea how I can exclude the alarms/incidents created from my custom table from this alert correlation?