Skip to content

Commit 19d6463

Browse files
Merge pull request #219261 from Shereen-Bhar/custom-alerts-configuration-in-sensor
moved screenshot
2 parents 5a67506 + d6111a2 commit 19d6463

File tree

3 files changed

+5
-3
lines changed

3 files changed

+5
-3
lines changed

articles/defender-for-iot/organizations/how-to-accelerate-alert-incident-response.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -102,8 +102,6 @@ Specify in the custom alert rule what action Defender for IT should take when th
102102

103103
1. On the sensor console, select **Custom alert rules** > **+ Create rule**.
104104

105-
:::image type="content" source="media/how-to-accelerate-alert-incident-response/create-custom-alert-rule.png" alt-text="Screenshot of the Create custom alert rule pane for creating custom alert rules." lightbox="media/how-to-accelerate-alert-incident-response/create-custom-alert-rule.png":::
106-
107105
1. In the **Create custom alert rule** pane that shows on the right, define the following fields:
108106

109107
|Name |Description |
@@ -113,9 +111,13 @@ Specify in the custom alert rule what action Defender for IT should take when th
113111
|**Message** | Define a message to display when the alert is triggered. Alert messages support alphanumeric characters and any traffic variables detected. <br> <br> For example, you might want to include the detected source and destination addresses. Use curly brackets (**{}**) to add variables to the alert message. |
114112
|**Direction** | Enter a source and/or destination IP address where you want to detect traffic. |
115113
|**Conditions** | Define one or more conditions that must be met to trigger the alert. Select the **+** sign to create a condition set with multiple conditions that use the **AND** operator. If you select a MAC address or IP address as a variable, you must convert the value from a dotted-decimal address to decimal format. <br><br> Note that the **+** sign is enabled only after selecting an **Alert protocol** from above. <br> You must add at least one condition in order to create a custom alert rule. |
116-
|**Detected** | Define a date and/or time range for the traffic you want to detect. You can customize the days and time range to fit with maintenance hours or set working hours. <br><br> :::image type="content" source="media/how-to-accelerate-alert-incident-response/detected.png" alt-text="Screenshot of the Detected field in the Create custom alert rule pane." lightbox="media/how-to-accelerate-alert-incident-response/detected.png"::: |
114+
|**Detected** | Define a date and/or time range for the traffic you want to detect. You can customize the days and time range to fit with maintenance hours or set working hours. |
117115
|**Action** | Define an action you want Defender for IoT to take automatically when the alert is triggered. |
118116

117+
For example:
118+
119+
:::image type="content" source="media/how-to-accelerate-alert-incident-response/create-custom-alert-rule.png" alt-text="Screenshot of the Create custom alert rule pane for creating custom alert rules." lightbox="media/how-to-accelerate-alert-incident-response/create-custom-alert-rule.png":::
120+
119121
1. Select **Save** when you're done to save the rule.
120122

121123
### Edit a custom alert rule
Loading

0 commit comments

Comments
 (0)