Skip to content

Commit 7f45a42

Browse files
authored
Update incident-investigation.md
1 parent 11b8faf commit 7f45a42

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

articles/sentinel/incident-investigation.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -97,8 +97,9 @@ Similarity is determined based on the following criteria:
9797
| **Similar entities** | An incident is considered similar to another incident if they both include the same [entities](entities.md). The more entities two incidents have in common,the more similar they're considered to be. |
9898
| **Similar rule** | An incident is considered similar to another incident if they were both created by the same [analytics rule](detect-threats-built-in.md). |
9999
| **Similar alert details** | An incident is considered similar to another incident if they share the same title, product name, and/or [custom details(surface-custom-details-in-alerts.md). |
100-
Incident similarity is calculated based on data from the 14 days prior to the last activity in the incident, that being the end time of the most recent alert in the incident.
101-
Incident similarity is recalculated every time you enter the incident details page, so the results might vary between sessions if new incidents were created or updated.
100+
101+
Incident similarity is calculated based on data from the 14 days prior to the last activity in the incident, that being the end time of the most recent alert in the incident. Incident similarity is also recalculated every time you enter the incident details page, so the results might vary between sessions if new incidents were created or updated.
102+
102103
For more information, see [Check for similar incidents in your environment](investigate-incidents.md#check-for-similar-incidents-in-your-environment).
103104

104105
### Top incident insights

0 commit comments

Comments
 (0)