Skip to content

Commit 0db74ea

Browse files
committed
more fixes , removed old article from toc
1 parent e3f47f0 commit 0db74ea

File tree

3 files changed

+6
-15
lines changed

3 files changed

+6
-15
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -109,9 +109,6 @@
109109
- name: Protect VMs
110110
displayName: manage, access, harden
111111
href: tutorial-protect-resources.md
112-
- name: Investigate and respond to security alerts
113-
displayName: triage, security, alerts, investigate,
114-
href: tutorial-security-incident.md
115112
- name: Investigate the health of your resources
116113
displayName: health, resources, outstanding, security, issues,
117114
href: investigate-resource-health.md

articles/defender-for-cloud/managing-and-responding-alerts.md

Lines changed: 6 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,10 @@ Defender for Cloud collects, analyzes, and integrates log data from your Azure,
1212

1313
This article shows you how to view and process Defender for Cloud's alerts and protect your resources.
1414

15-
When triaging security alerts, you should prioritize alerts based on their alert severity, addressing higher severity alerts first. Learn more about alerts severity in [How are alerts classified?](alerts-overview.md#how-are-alerts-classified).
15+
When triaging security alerts, you should prioritize alerts based on their alert severity, addressing higher severity alerts first. Learn more about [how alerts are classified](alerts-overview.md#how-are-alerts-classified).
1616

1717
> [!TIP]
18-
> You can connect Microsoft Defender for Cloud to most popular SIEM solutions including Microsoft Sentinel and consume the alerts from your tool of choice. Learn more in [Stream alerts to a SIEM, SOAR, or IT Service Management solution](export-to-siem.md).
18+
> You can connect Microsoft Defender for Cloud to SIEM solutions including Microsoft Sentinel and consume the alerts from your tool of choice. Learn more how to [stream alerts to a SIEM, SOAR, or IT Service Management solution](export-to-siem.md).
1919
2020
## Manage your security alerts
2121

@@ -25,25 +25,24 @@ When triaging security alerts, you should prioritize alerts based on their alert
2525

2626
:::image type="content" source="media/managing-and-responding-alerts/overview-page-alerts-links.png" alt-text="Screenshot that shows how the security alerts page from Microsoft Defender for Cloud's overview page looks.":::
2727

28-
1. (Optional) Filter the alerts list with any of the relevant filters. You can add additional filters with the **Add filter** option.
28+
1. (Optional) Filter the alerts list with any of the relevant filters. You can add extra filters with the **Add filter** option.
2929

3030
:::image type="content" source="./media/managing-and-responding-alerts/alerts-adding-filters-small.png" alt-text="Screenshot that shows you how to add filters to the alerts view." lightbox="./media/managing-and-responding-alerts/alerts-adding-filters-large.png":::
3131

3232
The list updates according to the filters selected. For example, you might you want to address security alerts that occurred in the last 24 hours because you're investigating a potential breach in the system.
3333

3434
## Investigate a security alert
3535

36-
Various options are available for each alert in order to assist you in your investigation.
36+
Each alert contains information regarding the alert that assists you in your investigation.
3737

3838
**To investigate a security alert**:
3939

4040
1. Select an alert. A side pane opens and shows a description of the alert and all the affected resources.
4141

42-
:::image type="content" source="./media/managing-and-responding-alerts/alerts-details-pane.png" alt-text="Screenshot of the high-level details view of a security alert.":::.
42+
:::image type="content" source="./media/managing-and-responding-alerts/alerts-details-pane.png" alt-text="Screenshot of the high-level details view of a security alert.":::
4343

4444
1. Review the high-level information about the security alert.
4545

46-
This pane shows:
4746
- Alert severity, status, and activity time
4847
- Description that explains the precise activity that was detected
4948
- Affected resources
@@ -64,10 +63,7 @@ Various options are available for each alert in order to assist you in your inve
6463

6564
:::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Take action tab.":::
6665

67-
If you need further details:
68-
69-
- Contact the resource owner to verify whether the detected activity is a false positive.
70-
- Investigate the raw logs generated by the attacked resource
66+
For further details contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
7167

7268
## Change the status of multiple security alerts at once
7369

articles/defender-for-cloud/release-notes-archive.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2984,8 +2984,6 @@ Azure Security Center's security alerts page was redesigned to provide:
29842984
- **Alerts from Azure Resource Graph** - you can query alerts in Azure Resource Graph, the Kusto-like API for all of your resources. This is also useful if you're building your own alerts dashboards. [Learn more about Azure Resource Graph](../governance/resource-graph/index.yml).
29852985
- **Create sample alerts feature** - To create sample alerts from the new alerts experience, see [Generate sample Azure Defender alerts](alert-validation.md#generate-sample-security-alerts).
29862986

2987-
:::image type="content" source="media/managing-and-responding-alerts/alerts-page.png" alt-text="Azure Security Center's security alerts list":::
2988-
29892987
### Kubernetes workload protection recommendations released for general availability (GA)
29902988

29912989
We're happy to announce the general availability (GA) of the set of recommendations for Kubernetes workload protections.

0 commit comments

Comments
 (0)