Skip to content

Commit 0852510

Browse files
committed
Minor edits
1 parent f2b02fb commit 0852510

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

articles/sentinel/domain-based-essential-solutions.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,10 +22,10 @@ In the content hub, there are multiple product solutions for different domain ca
2222
- Most of the major network products have a common basic set of firewall alerts that includes malicious threats coming from unusual IP addresses. The analytic rule template is, in general, duplicated for each of the "Security - Network" category of product solutions. If you're running multiple network products, you need to check and configure multiple analytic rules individually, which is inefficient. You'd also get alerts for each rule configured and might end up with alert fatigue.
2323
- If you have duplicative hunting queries, you might have less performant hunting experiences with the run-all mode of hunting. These duplicative hunting queries also introduce inefficiencies for threat hunters to select and run similar queries.
2424

25-
You might consider Microsoft essential solution for the following reasons:
25+
You might consider Microsoft essential solutions for the following reasons:
2626

2727
- A normalized schema makes it easier for you to query incident details. You don't have to remember different vendor syntax for similar log attributes.
28-
- If you don't have to manage content for multiple solutions, it makes use case deployment and incident handling much easier.
28+
- If you don't have to manage content for multiple solutions, use case deployment and incident handling is much easier.
2929
- A consolidated workbook view gives you better environment visibility and possible query time parsing with high performing ASIM parsers.
3030

3131
## ASIM schemas supported

0 commit comments

Comments
 (0)