Skip to content

Commit 276c468

Browse files
committed
Content review
1 parent 920bf5c commit 276c468

File tree

1 file changed

+6
-5
lines changed

1 file changed

+6
-5
lines changed

articles/sentinel/bookmarks.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,6 @@ appliesto:
1010
- Microsoft Sentinel in the Microsoft Defender portal
1111
- Microsoft Sentinel in the Azure portal
1212

13-
1413
#Customer intent: As a security analyst, I want to create and manage hunting bookmarks so that I can preserve and collaborate on relevant threat investigation data.
1514

1615
---
@@ -19,13 +18,16 @@ appliesto:
1918

2019
Hunting bookmarks in Microsoft Sentinel helps you preserve the queries and query results that you deem relevant. You can also record your contextual observations and reference your findings by adding notes and tags. Bookmarked data is visible to you and your teammates for easy collaboration. For more information, see [Bookmarks](hunting.md#bookmarks-to-keep-track-of-data).
2120

21+
>[!NOTE]
22+
> Bookmarks can only be created in the Azure portal. While you can't add bookmarks in the Microsoft Defender portal, you can see bookmarks that were already created.
23+
2224
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
2325

24-
## Add a bookmark
26+
## Add a bookmark (Azure portal only)
2527

2628
Create a bookmark to preserve the queries, results, your observations, and findings.
2729

28-
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Threat management** select **Hunting**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Threat management** > **Hunting**.
30+
1. Under **Threat management**, select **Hunting**.
2931
1. From the **Queries** tab, select one or more of the hunting queries.
3032
1. From the top command bar, select **Run selected queries**.
3133

@@ -83,7 +85,7 @@ Visualize your bookmarked data by launching the investigation experience in whic
8385

8486
For instructions to use the investigation graph, see [Use the investigation graph to deep dive](investigate-cases.md#use-the-investigation-graph-to-deep-dive).
8587

86-
## Add bookmarks to a new or existing incident
88+
## Add bookmarks to a new or existing incident (Azure portal only)
8789

8890
Add bookmarks to an incident from the bookmarks tab on the **Hunting** page.
8991

@@ -103,7 +105,6 @@ Add bookmarks to an incident from the bookmarks tab on the **Hunting** page.
103105
1. Select the incident with your bookmark and **View full details**.
104106
1. On the incident page, in the left pane, select the **Bookmarks**.
105107

106-
107108
## View bookmarked data in logs
108109

109110
View bookmarked queries, results, or their history.

0 commit comments

Comments
 (0)