Sentinel ingestion issue

Incident Report for Kudelski Security

Resolved

The incident has been resolved and services are back to normal. We thank you for your patience and understanding.
Posted Jan 26, 2024 - 08:22 UTC

Monitoring

Microsoft issue is getting solved, the CFC is receiving alerts as expected. We will monitor the situation and re-investigate alerts that might have been missed during this period.
Posted Jan 26, 2024 - 07:39 UTC

Update

We continue to follow the situation, our teams are manually monitoring the impacted technologies to mitigate the risk of missed incident.
Posted Jan 26, 2024 - 05:20 UTC

Identified

Microsoft is currently experiencing degradation in the EU region. It is preventing the CFC to receive events from Microsoft Defender product and Sentinel in a timely manner.
Microsoft identified the issue, they are currently observing intermittent application crashes. They are continuing to scale out the cluster and restore nodes to allow requests to be processed successfully.

The CFC is monitoring the situation and alerts collection continues when resources are available.
Posted Jan 26, 2024 - 04:12 UTC
This incident affected: Security Alert / Event Ingestion Pipeline / Managed System Access.