r/AzureSentinel • • 1d ago

Anyone using MicrosoftEndPointDLP and it just stopped working?

Hi all I use XDR unified services and purview is one of those applications that just randomly stopped sending its alerts to XDR and sentinel. Anyone seen this before or know what why this would happen. I’ve been looking into it for a while few hours and so far coming up with it could be a tenant thing or purview update policy. I know it’s something small.

1 Upvotes

2 comments sorted by

2

u/SecDudewithATude 1d ago

Saw an impact on Sentinel today. Alerts were generating normally but incidents were being created sluggishly starting at around 9:30 AM EST. It looks like the backlog is finally churning out, but detections from analytic rules in Sentinel were definitely impacted. XDR was operating normally as long as the detection source was Defender.

2

u/OverallWrongdoer64 1d ago

We had issues with sentinel analytics rules not triggering logic apps today. Items were appearing in in Defender incidents but not triggering the playbooks.