Skip to content

Commit db1bbba

Browse files
authored
Update incidenttasks.md
1 parent 3a12db6 commit db1bbba

File tree

1 file changed

+1
-17
lines changed

1 file changed

+1
-17
lines changed

Docs/incidenttasks.md

+1-17
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,4 @@
11
# Sentinel Triage AssistanT (STAT) :hospital: - Incident Tasks (Preview)
22

33
> [!NOTE]
4-
> STAT documentation is being relocated to the builin [Wiki](https://github.com/briandelmsft/SentinelAutomationModules/wiki)
5-
6-
Microsoft Sentinel now supports the addition of [tasks](https://learn.microsoft.com/azure/sentinel/work-with-tasks) to incidents. Tasks have a more prominent place in the incident interface than comments do so it can help draw attention to important steps for an analyst to follow.
7-
8-
STAT now has support to add incident tasks to the corresponding incident.
9-
10-
Tasks will only be added if there is a finding from STAT. For example, if the KQL module is used and no records are found based on your search, no task will be added to the incident.
11-
12-
To use the Incident Tasks feature, when adding a supported module to your Logic app, select the *Add new parameter* option and check off *AddIncidentTask* and *IncidentTaskInstructions*.
13-
14-
|Setting|Description|
15-
|---|---|
16-
|AddIncidentTask|When true, an incident task will be added if this module finds any relevant data|
17-
|IncidentTaskInstructions|The instructions placed here will be added to the incident task for your analyst to review|
18-
19-
---
20-
[Documentation Home](readme.md)
4+
> STAT documentation is now located in the built-in [Wiki](https://github.com/briandelmsft/SentinelAutomationModules/wiki/Modules#incident-tasks)

0 commit comments

Comments
 (0)