Skip to content

Commit 1342120

Browse files
Merge pull request #226543 from berlihie/patch-3
Alerts are displayed even if the impacted resource was deleted
2 parents a4b3e08 + cf2202e commit 1342120

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

articles/defender-for-cloud/alerts-overview.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,8 @@ Security alerts are the notifications generated by Defender for Cloud and Defend
1717
- Security alerts are triggered by advanced detections in Defender for Cloud, and are available when you enable Defender for Cloud [Defender plans](defender-for-cloud-introduction.md#protect-cloud-workloads).
1818
- Each alert provides details of affected resources, issues, and remediation recommendations.
1919
- Defender for Cloud classifies alerts and prioritizes them by severity in the Defender for Cloud portal.
20-
- Alerts data is retained for 90 days.
20+
```suggestion
21+
- Alerts are displayed for 90 days, even if the resource related to the alert was deleted during that time. This is because the alert might indicate a potential breach to your organization that needs to be further investigated.
2122
- Alerts can be exported to CSV format, or directly injected into Microsoft Sentinel.
2223
- Defender for Cloud leverages the [MITRE Attack Matrix](https://attack.mitre.org/matrices/enterprise/) to associate alerts with their perceived intent, helping formalize security domain knowledge.
2324

0 commit comments

Comments
 (0)