If during the investigation you found an event that is related to the alert being investigated, you can link this event to the alert manually.
You can link an event to an alert that has any status other than Closed.
To link an event to an alert:
The Alert details window opens.
The Threat hunting section opens. By default, the event table contains events related to the selected alert.
The event table contains only events related to tenants that you have access to.
You can select predefined ranges relative to the current date and time, specify a custom range by using the Range start and Range end fields, or by selecting dates in the calendar.
The selected events are linked to the alert.
Page top