Is there a way to acknowledge Alert so the email notifications are no longer triggered? For example Malware was stopped on a PC, alert triggered an email notification that malware was detected and stopped/remediated .. I looked at the alert and issue and all is OK, .but the alert keeps sending email messages?
I am experiencing similar situation. Malware found and quarantined on OMS-integrated server by Windows Defender which triggered an alert.
Windows Defender alert acknowledged locally on the server, quarantine has been emptied followed by full system scan. Despite all this, OMS alerts are generated approximately once every hour because Windows Defender ThreatStatus keeps flipping between "No threats detected" and "Active" for previous threat which was found and acknowledged by system administrator.