Incident management can quickly become messy when multiple analysts are working through the queue. Custom incident labels in Microsoft Sentinel help bring order to the chaos. They make it easy to group, prioritize, and track related activity across your investigations.
Breakdown
Labels are flexible identifiers you can assign to incidents. Here’s how to make the most of them:
- Open an incident and select Manage labels.
- Add labels that align with your workflow such as Credential Theft, Needs Review, or Phishing Confirmed.
- You can also create automation rules to apply labels automatically when certain criteria are met. For example, any alert with “Suspicious Logon” in the title could receive the Authentication label.
- Once applied, labels become filterable in the Incidents blade, making it easier to find trends or assign work efficiently.
Consistent labelling helps you analyse response metrics, visualize patterns, and improve reporting.
Automation and reporting
With the labels assigned to your incidents, you can then use these to trigger automation on incidents, such as assigning specific labels to certain SOC analysts, or running playbooks against incidents based on the tags. (Or preventing automation if you tag a label.)
Building upon this, you could then use the labels to filter reporting or to provide better contextualised information in board reports.
Call to Action
Add a few meaningful labels to your incidents this week and encourage your team to do the same. What labelling strategy works best for you? Share your ideas and let’s build a more structured SOC process together.