

In sentinel indicators coming from two TI sources (MS defender and ThreatConnect), if same indicators come from both sources, is there a way to deduplicate it or can Sentinel duplicate them by default. ex. IP is coming from two feeds in Sentinel, will it have two instances.

If in Sentinel, indicators coming from two different Threat Intelligence (TI) sources, is deduplication ensured so that the same indicator (e.g., an IP address, domain, file hash) is not counted multiple times or processed redundantly.

本文标签: duplicatesDeduplication of Indicators in SentinelStack Overflow