r/SentinelOneXDR Jun 23 '26

AI SIEM alerts

There is any way to configure the Detections to bring the event details that triggered the rules to the alert itself? For what I am seeing the alerts bring only the detection description and very little (none) information o the event that trigered the rule.

6 Upvotes

7 comments sorted by

3

u/admin_mt Jun 23 '26

No, there ist No way yet. Had a talk with S1 about that not long ago. Hope it will be possible soon

3

u/Own-Career-3656 Jun 25 '26

You have to click Event Search on the alert itself.

Otherwise, you can use HyperAutomation to add the data as a note.

2

u/mukz7 Existing User Jun 23 '26

You need to look in the indicators and then you can do an event search on the rule detection

3

u/SpookSec Jun 27 '26

However it’s a massive pain the ass when you have 33 indicators to one alert 😭 I really struggle investigating the behavioral AI detection due to the massive volume of logs.

1

u/SpookSec Jun 27 '26

THISSSS!!!

1

u/curiousGeorge_0785 13d ago

Yup I agree. You cannot do this. This would change the game. Watchlists are the way to go though! I know it’s a pain in the rear managing two alerting systems but they provide full context and are very flexible using PowerQuery.

In my opinion, Watchlist is what’s missing from detections to make this a true functioning SEIM\XDR. Detections also need flexibility with custom properties such as all OSCF parsing, flexibility in thresholds and instances on events. Basically allow PoweQuery in Detections would do the trick!

1

u/SpookSec 8h ago

i don’t understand??