Skip to content

Commit 637ff8f

Browse files
authored
Merge pull request #292302 from batamig/investigate-incidents-simplify
simplifying incidents
2 parents 4038263 + cf4c254 commit 637ff8f

File tree

5 files changed

+329
-273
lines changed

5 files changed

+329
-273
lines changed

articles/sentinel/TOC.yml

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -912,13 +912,13 @@
912912
- name: Overview
913913
href: kusto-overview.md
914914
- name: Query best practices
915-
href: /kusto/query/best-practices?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
915+
href: /kusto/query/best-practices?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true
916916
- name: SQL to KQL cheat sheet
917-
href: /kusto/query/sql-cheat-sheet?view=microsoft-fabric
917+
href: /kusto/query/sql-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true
918918
- name: Splunk to KQL cheat sheet
919-
href: /kusto/query/splunk-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
919+
href: /kusto/query/splunk-cheat-sheet?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true
920920
- name: KQL quick reference
921-
href: /kusto/query/kql-quick-reference?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json
921+
href: /kusto/query/kql-quick-reference?toc=/azure/sentinel/TOC.json&bc=/azure/sentinel/breadcrumb/toc.json&view=microsoft-sentinel&preserve-view=true
922922
- name: Other KQL resources
923923
href: kusto-resources.md
924924
- name: Create custom query
@@ -945,7 +945,10 @@
945945
items:
946946
- name: Overview
947947
href: incident-investigation.md
948-
- name: Investigate incidents
948+
- name: Triage and manage your incidents
949+
href: incident-navigate-triage.md
950+
displayName: close incidents, search incidents, comment on incidents
951+
- name: Investigate incidents in depth
949952
href: investigate-incidents.md
950953
- name: Tutorial - Investigate with UEBA
951954
href: investigate-with-ueba.md

0 commit comments

Comments
 (0)