Skip to content

Commit 1509937

Browse files
authored
Merge pull request #194638 from MicrosoftDocs/main
Merge main to live Sunday at 4 PM.
2 parents d32be5a + 158cfce commit 1509937

File tree

7 files changed

+16
-19
lines changed

7 files changed

+16
-19
lines changed

articles/azure-monitor/alerts/itsmc-definition.md

Lines changed: 15 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -19,17 +19,17 @@ Before you can create a connection, you need to install ITSMC.
1919

2020
1. In the Azure portal, select **Create a resource**:
2121

22-
![Screenshot that shows the menu item for creating a resource.](media/itsmc-overview/azure-add-new-resource.png)
22+
![Screenshot of the menu item for creating a resource.](media/itsmc-overview/azure-add-new-resource.png)
2323

24-
2. Search for **IT Service Management Connector** in Azure Marketplace. Then select **Create**:
24+
1. Search for **IT Service Management Connector** in Azure Marketplace. Then select **Create**:
2525

2626
![Screenshot that shows the Create button in Azure Marketplace.](media/itsmc-overview/add-itsmc-solution.png)
2727

28-
3. In the **LA Workspace** section, select the Log Analytics workspace where you want to install ITSMC.
28+
1. In the **LA Workspace** section, select the Log Analytics workspace where you want to install ITSMC.
2929
> [!NOTE]
3030
> You can install ITSMC in Log Analytics workspaces only in the following regions: East US, West US 2, South Central US, West Central US, US Gov Arizona, US Gov Virginia, Canada Central, West Europe, South UK, Southeast Asia, Japan East, Central India, and Australia Southeast.
3131
32-
4. In the **Log Analytics workspace** section, select the resource group where you want to create the ITSMC resource:
32+
1. In the **Log Analytics workspace** section, select the resource group where you want to create the ITSMC resource:
3333

3434
![Screenshot that shows the Log Analytics workspace section.](media/itsmc-overview/itsmc-solution-workspace.png)
3535

@@ -46,8 +46,6 @@ After you've installed ITSMC, you must prep your ITSM tool to allow the connecti
4646

4747
- [ServiceNow](./itsmc-connections-servicenow.md)
4848
- [System Center Service Manager](./itsmc-connections-scsm.md)
49-
- [Cherwell](./itsmc-connections-cherwell.md)
50-
- [Provance](./itsmc-connections-provance.md)
5149

5250
After you've prepped your ITSM tool, complete these steps to create a connection:
5351

@@ -61,12 +59,10 @@ After you've prepped your ITSM tool, complete these steps to create a connection
6159

6260
1. Select **Add Connection**.
6361

64-
1. Specify the connection settings according to the ITSM product that you're using:
62+
1. Specify the connection settings for the ITSM product that you're using:
6563

6664
- [ServiceNow](./itsmc-connections-servicenow.md)
6765
- [System Center Service Manager](./itsmc-connections-scsm.md)
68-
- [Cherwell](./itsmc-connections-cherwell.md)
69-
- [Provance](./itsmc-connections-provance.md)
7066

7167
> [!NOTE]
7268
> By default, ITSMC refreshes the connection's configuration data once every 24 hours. To refresh your connection's data instantly to reflect any edits or template updates that you make, select the **Sync** button on your connection's pane:
@@ -88,27 +84,28 @@ Certain work item types can use templates that you define in the ITSM tool. By u
8884

8985
To create an action group:
9086

91-
1. In the Azure portal, select **Alerts**.
92-
2. On the menu at the top of the screen, select **Manage actions**:
87+
1. In the Azure portal, select **Monitor** and then **Alerts**.
88+
1. On the menu at the top of the screen, select **Manage actions**:
9389

9490
![Screenshot that shows the Manage actions menu item.](media/itsmc-overview/action-groups-selection-big.png)
9591

92+
1. In the **Action groups** window, select **+Create**.
9693
The **Create action group** window appears.
9794

98-
3. Select the **Subscription** and **Resource group** where you want to create your action group. Provide values in **Action group name** and **Display name** for your action group. Then select **Next: Notifications**.
95+
1. Select the **Subscription** and **Resource group** where you want to create your action group. Provide values in **Action group name** and **Display name** for your action group. Then select **Next: Notifications**.
9996

10097
![Screenshot that shows the Create action group window.](media/itsmc-overview/action-groups-details.png)
10198

102-
4. On the **Notifications** tab, select **Next: Actions**.
103-
5. On the **Actions** tab, select **ITSM** in the **Action Type** list. For **Name**, provide a name for the action. Then select the pen button that represents **Edit details**.
99+
1. In the **Notifications** tab, select **Next: Actions**.
100+
1. In the **Actions** tab, select **ITSM** in the **Action Type** list. For **Name**, provide a name for the action. Then select the pen button that represents **Edit details**.
104101

105102
![Screenshot that shows selections for creating an action group.](media/itsmc-definition/action-group-pen.png)
106103

107-
6. In the **Subscription** list, select the subscription that contains your Log Analytics workspace. In the **Connection** list, select your ITSM connector name. It will be followed by your workspace name. An example is *MyITSMConnector(MyWorkspace)*.
104+
1. In the **Subscription** list, select the subscription that contains your Log Analytics workspace. In the **Connection** list, select your ITSM connector name. It will be followed by your workspace name. An example is *MyITSMConnector(MyWorkspace)*.
108105

109-
7. Select a **Work Item** type.
106+
1. Select a **Work Item** type.
110107

111-
8. In the last section of the interface for creating an ITSM action group, you can define how many work items will be created for each alert.
108+
1. In the last section of the interface for creating an ITSM action group, you can define how many work items will be created for each alert.
112109

113110
> [!NOTE]
114111
> This section is relevant only for log search alerts. For all other alert types, you'll create one work item per alert.
@@ -140,7 +137,7 @@ To create an action group:
140137
* **Use default fields**: Using a set of fields and values that will be sent automatically as a part of the payload to ServiceNow. Those fields are not flexible and the values are defined in ServiceNow lists.
141138
* **Use saved templates from ServiceNow**: Using a predefine set of fields and values that was defined as a part of a template definition in ServiceNow. If you already defined the template in ServiceNow you can use it from the **Template** list otherwise you can define it in ServiceNow, for more [details](#define-a-template).
142139

143-
10. Select **OK**.
140+
1. Select **OK**.
144141

145142
When you create or edit an Azure alert rule, use an action group, which has an ITSM action. When the alert triggers, the work item is created or updated in the ITSM tool.
146143

10.6 KB
Loading
20.8 KB
Loading
33.4 KB
Loading
68.9 KB
Loading
23.7 KB
Loading

articles/sentinel/ueba-enrichments.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -208,7 +208,7 @@ While the initial synchronization may take a few days, once the data is fully sy
208208

209209
- Group and role information is synchronized between the **IdentityInfo** table and Azure AD daily.
210210

211-
- Every 21 days, Microsoft Sentinel re-synchronizes with your entire Azure AD to ensure that stale records are fully updated.
211+
- Every 14 days, Microsoft Sentinel re-synchronizes with your entire Azure AD to ensure that stale records are fully updated.
212212

213213
- Default retention time in the **IdentityInfo** table is 30 days.
214214

0 commit comments

Comments
 (0)