Skip to content

Commit 7c5f24a

Browse files
committed
What's new merging
1 parent ecbbf7f commit 7c5f24a

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/sentinel/whats-new.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,8 +19,18 @@ See these [important announcements](#announcements) about recent changes to feat
1919

2020
## February 2023
2121

22+
- [New behavior for alert grouping in analytics rules](#new-behavior-for-alert-grouping-in-analytics-rules) (in [Announcements](#announcements) section below)
23+
- [Audit and monitor the health of your analytics rules (Preview)](#audit-and-monitor-the-health-of-your-analytics-rules-preview)
2224
- [Advanced scheduling for analytics rules (Preview)](#advanced-scheduling-for-analytics-rules-preview)
2325

26+
### Audit and monitor the health of your analytics rules (Preview)
27+
28+
Microsoft Sentinel's **health monitoring feature is now available for analytics rules** in addition to automation rules, playbooks, and data connectors. Also now available for the first time, and currently only for analytics rules, is Microsoft Sentinel's **audit feature**. The audit feature collects information about any changes made to Sentinel resources (analytics rules) so that you can discover any unauthorized actions or tampering with the service.
29+
30+
Learn more about [auditing and health monitoring in Microsoft Sentinel](health-audit.md):
31+
- [Turn on auditing and health monitoring for Microsoft Sentinel (preview)](enable-monitoring.md)
32+
- [Monitor the health and audit the integrity of your analytics rules](monitor-analytics-rule-integrity.md)
33+
2434
### Advanced scheduling for analytics rules (Preview)
2535

2636
To give you more flexibility in scheduling your analytics rule execution times and to help you avoid potential conflicts, Microsoft Sentinel now allows you to determine when newly created analytics rules will run for the first time. The default behavior is as it has been: for them to run immediately upon creation.

0 commit comments

Comments
 (0)