Skip to content

Commit 374fadf

Browse files
add ingestion rule image
1 parent 9b7bc62 commit 374fadf

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

articles/sentinel/understand-threat-intelligence.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -157,10 +157,17 @@ Take full control of threat intelligence feeds by filtering and optimizing the i
157157
| Ingestion rule use case | Description |
158158
|---|---|
159159
| Reduce noise | Filter out old threat intelligence not updated for 6 months that also has low confidence. |
160-
| Extend validity date | Promote high fidelity IOCs from trusted source by extending their `Valid until` by 30 days. |
160+
| Extend validity date | Promote high fidelity IOCs from trusted sources by extending their `Valid until` by 30 days. |
161161
| Remember the old days | The new threat actor taxonomy is great, but some of the analysts want to be sure to tag the old names. |
162162

163-
For more information, see [Work with threat intelligence ingestion rules](work-with-threat-indicators.md#curate-threat-intelligence-with-ingestion-rules).
163+
:::image type="content" source="media/understand-threat-intelligence/ingestion-rules-overview.png" alt-text="Screenshot shows four ingestion rules matching the use cases.":::
164+
165+
Keep in mind the following tips for using ingestion rules:
166+
- All rules apply in order. Threat intelligence objects being ingested will get processed by each rule until a `Delete` action is taken.
167+
- The `Delete` action means the threat intelligence object is skipped for ingestion, meaning it's removed from the pipeline. Any previous versions of the object already ingested aren't affected.
168+
- New and edited rules take up to 15 minutes to take effect.
169+
170+
For more information, see [Work with threat intelligence ingestion rules](work-with-threat-indicators.md#optimize-threat-intelligence-feeds-with-ingestion-rules).
164171

165172
### Create relationships
166173

0 commit comments

Comments
 (0)