Forum Discussion

RayO's avatar
RayO
Copper Contributor
Jun 05, 2025

Lack of alerts in Sentinel

Hello,

I am troubleshooting a lack of alerts and incidents in my Sentinel deployment.

When I look at the Micrsoft Defender XDR connector, I see plenty of events like DeviceEvents, DeviceInfo, IdentityLogonEvents, etc.  However, the entries for:

SecurityIncident--

SecurityAlert--

AlertInfo--

AlertEvidence--

all show grey with a disconnected connector showing. I've been over the onboarding documentation several times and can't find what I'm missing.

Has anyone else experienced this who can point me in the right direction of what to check?

Thanks!

No RepliesBe the first to reply

Resources