bf273b959a
An XDR incident is not finished when it is created. Alerts keep joining it, an analyst changes its status, its severity is raised. A creation_time watermark fetches it once, the watermark moves past it, and nothing that happens afterwards ever reaches Riposte — which is precisely the content the full fetch exists to bring in. modified_after filters and sorts on modification_time instead, so an incident comes back on every change and dedup on incident_id turns the second visit into an enrichment of the incident already there. It is now what the ingest hint prefills; created_after stays for a one-shot backfill. Worth knowing about that enrichment: it merges context and can fill a detection anchor that was missing, but it does not restate the incident's severity or status. An incident XDR later raises to critical stays at the severity it was ingested with. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>