You can link one or multiple alerts to an incident for the following reasons:
You can link an alert to an incident if the alert has any status other than Closed. When linked to an incident, an alert loses its current status and gains the special status In incident. If you link alerts that are currently linked to other incidents, the alerts are unlinked from the current incidents, because an alert can be linked to only one incident.
Alerts can only be linked to an incident that belongs to the same tenant.
Alerts can be linked to an incident manually or automatically.
Linking alerts manually
To link alerts to an existing or new incident:
Alternatively, click an alert to display its details and click the Link to incident button in the toolbar at the top.
Alternatively, click an alert to display its details and click the Create incident button in the toolbar at the top.
The selected alerts are linked to an existing or new incident.
Linking alerts automatically
If you want alerts to automatically link to an incident, you have to configure segmentation rules.