The rule reliably generates incidents, but the resulting incidents show no entities on the investigation graph. You need Microsoft Sentinel to recognize the Computer value as a Host entity and the TargetUserName value as an Account entity so that future incidents are automatically enriched. Which action should you take while editing the analytics rule?
Enable User and Entity Behavior Analytics (UEBA) for the workspace.
Add Computer and TargetUserName as custom incident details in the rule settings.
Turn on alert grouping and choose to group alerts by entity values.
Use the Entities mapping section of the rule wizard to map Computer to Host and TargetUserName to Account.
Microsoft Sentinel does not infer entities from a query automatically. For each analytics rule you must explicitly tell Sentinel which columns represent which entity types. The Analytics rule wizard provides an Entities mapping (sometimes labeled Entity mapping) section where you choose an entity type-such as Host, Account, IP, URL-and then select the corresponding column from your query results. Mapping Computer to the Host entity type and TargetUserName to the Account entity type causes those values to appear as entities in alerts and incidents, enabling investigation graph visualization and UEBA enrichment. Alert grouping, custom details, or simply enabling UEBA do not create the required entity records unless the entity mapping step is completed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are entities in Microsoft Sentinel and how do they help in investigations?
Open an interactive chat with Bash
What is the Entities Mapping feature in Microsoft Sentinel analytics rules?
Open an interactive chat with Bash
How does User and Entity Behavior Analytics (UEBA) work in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Configure protections and detections
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .