Skip to content

Commit 82e1883

Browse files
committed
Added preview disclaimers
1 parent 4af1e93 commit 82e1883

File tree

2 files changed

+15
-11
lines changed

2 files changed

+15
-11
lines changed

articles/sentinel/customize-alert-details.md

Lines changed: 13 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,10 @@ With the **alert details** feature, you can override these and other default pro
1919

2020
- Customize the severity, tactics, and other properties of a given instance of an alert (see the full list of properties below) with the values of any relevant fields from the query output. If the selected fields are empty or have values that don't match the field data type, the respective alert properties will revert to their defaults (for tactics and severity, those specified in the first page of the wizard).
2121

22+
> [!IMPORTANT]
23+
> Some alert details' customizability (see those so indicated below) are currently in **PREVIEW**. See the [Supplemental Terms of Use for Microsoft Azure Previews](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) for additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
24+
25+
2226
Follow the procedure detailed below to use the alert details feature. These steps are part of the [analytics rule creation wizard](detect-threats-custom.md), but they're addressed here independently to address the scenario of adding or changing alert details in an existing analytics rule.
2327

2428
## How to customize alert details
@@ -53,15 +57,15 @@ Follow the procedure detailed below to use the alert details feature. These step
5357
- Description
5458
- AlertSeverity
5559
- Tactics
56-
- Techniques (New)
57-
- AlertLink (New)
58-
- ConfidenceLevel (New)
59-
- ConfidenceScore (New)
60-
- ExtendedLinks (New)
61-
- ProductComponentName (New)
62-
- ProductName (New)
63-
- ProviderName (New)
64-
- RemediationSteps (New)
60+
- Techniques (Preview)
61+
- AlertLink (Preview)
62+
- ConfidenceLevel (Preview)
63+
- ConfidenceScore (Preview)
64+
- ExtendedLinks (Preview)
65+
- ProductComponentName (Preview)
66+
- ProductName (Preview)
67+
- ProviderName (Preview)
68+
- RemediationSteps (Preview)
6569

6670
If you change your mind, or if you made a mistake, you can remove an alert detail by clicking the trash can icon next to the **Alert property/Value** pair, or delete the free text from the **Alert Name/Description Format** fields.
6771

articles/sentinel/whats-new.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@ The listed features were released in the last three months. For information abou
1818

1919
## November 2022
2020

21-
- [Customize more alert properties](#customize-more-alert-properties)
21+
- [Customize more alert properties (Preview)](#customize-more-alert-properties-preview)
2222
- [Common Event Format (CEF) via AMA (Preview)](#common-event-format-cef-via-ama-preview)
2323
- [Monitor the health of automation rules and playbooks](#monitor-the-health-of-automation-rules-and-playbooks)
2424
- [Updated Microsoft Sentinel Logstash plugin](#updated-microsoft-sentinel-logstash-plugin)
2525

26-
### Customize more alert properties
26+
### Customize more alert properties (Preview)
2727

2828
Alerts generated by a given analytics rule - and all incidents created as a result - inherit the name, description, severity, and tactics defined in the rule, without regard to the particular content of a specific instance of the alert.
2929

0 commit comments

Comments
 (0)