Skip to content

Commit 411d4b0

Browse files
Merge pull request #293467 from yelevin/patch-2
Update customize-alert-details.md
2 parents 8535728 + b1cd0b5 commit 411d4b0

File tree

1 file changed

+10
-5
lines changed

1 file changed

+10
-5
lines changed

articles/sentinel/customize-alert-details.md

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -81,14 +81,19 @@ Follow the procedure detailed below to use the alert details feature. These step
8181
| **ConfidenceLevel** (Preview) | One of the following values: <br>- **Low**<br>- **High**<br>- **Unknown** |
8282
| **ConfidenceScore** (Preview) | Integer, between **0**-**1** (inclusive) |
8383
| **ExtendedLinks** (Preview) | String |
84-
| **ProductComponentName** (Preview) | String |
85-
| **ProductName** (Preview)<br>\* See note following this table | String |
86-
| **ProviderName** (Preview) | String |
84+
| **ProductComponentName** (Preview)<br>\* See Caution notes following this table | String |
85+
| **ProductName** (Preview)<br>\* See Caution notes following this table | String |
86+
| **ProviderName** (Preview)<br>\* See Caution notes following this table | String |
8787
| **RemediationSteps** (Preview) | String |
8888

89-
> [!NOTE]
89+
> [!CAUTION]
9090
>
91-
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, **do not customize** the *ProductName* field for alerts from Microsoft sources. Doing so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
91+
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal:
92+
> - **Do not customize** the *ProductName* field for alerts from Microsoft sources. Doing so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
93+
>
94+
> - The *ProductComponentName* and *ProviderName* fields are no longer available to be customized.
95+
>
96+
> If any of these customizations already exist in any of your rules, remove the customizations to maintain compatibility and avoid unexpected results.
9297
9398
If you change your mind, or if you made a mistake, you can remove an alert detail by clicking the trash can icon next to the **Alert property/Value** pair, or delete the free text from the **Alert Name/Description Format** fields.
9499

0 commit comments

Comments
 (0)