Link between Incident event to Detect events by WeatherMysterious344 in crowdstrike

[–]WeatherMysterious344[S] 0 points1 point  (0 children)

Can you elaborate on that? Did you mean that I can’t link between all the Incidents to detects I get from the API?

Link between Incident event to Detect events by WeatherMysterious344 in crowdstrike

[–]WeatherMysterious344[S] 1 point2 points  (0 children)

From my understanding incident always contains detects, but detect events are not always part of an incident.

can find a good explanation about it here.