1 - From the Investigation blade, select Insights 2 - From the Investigation blade, select the entity that represents VM1. 3 - From the details pane of the incident, select Investigate. Reference: https://github.com/Azure/Azure-Sentinel/wiki/Investigation-Insights---Overview https://docs.microsoft.com/en-us/azure/sentinel/investigate-cases