|
912 | 912 | - name: Overview
|
913 | 913 | href: kusto-overview.md
|
914 | 914 | - name: Query best practices
|
915 |
| - href: /kusto/query/best-practices?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 915 | + href: /kusto/query/best-practices?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true |
916 | 916 | - name: SQL to KQL cheat sheet
|
917 |
| - href: /kusto/query/sql-cheat-sheet?view=microsoft-fabric |
| 917 | + href: /kusto/query/sql-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true |
918 | 918 | - name: Splunk to KQL cheat sheet
|
919 |
| - href: /kusto/query/splunk-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 919 | + href: /kusto/query/splunk-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true |
920 | 920 | - name: KQL quick reference
|
921 |
| - href: /kusto/query/kql-quick-reference?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json |
| 921 | + href: /kusto/query/kql-quick-reference?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true |
922 | 922 | - name: Other KQL resources
|
923 | 923 | href: kusto-resources.md
|
924 | 924 | - name: Create custom query
|
|
945 | 945 | items:
|
946 | 946 | - name: Overview
|
947 | 947 | href: incident-investigation.md
|
948 |
| - - name: Investigate incidents |
| 948 | + - name: Triage and manage your incidents |
| 949 | + href: incident-navigate-triage.md |
| 950 | + displayName: close incidents, search incidents, comment on incidents |
| 951 | + - name: Investigate incidents in depth |
949 | 952 | href: investigate-incidents.md
|
950 | 953 | - name: Tutorial - Investigate with UEBA
|
951 | 954 | href: investigate-with-ueba.md
|
|
0 commit comments