Skip to content

Commit 9ccb502

Browse files
authored
disclaimer - alerts are displayed even if the impacted resource was deleted
------- cc: @bmansheim
1 parent 5379ed5 commit 9ccb502

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

articles/defender-for-cloud/alerts-overview.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,8 @@ Security alerts are the notifications generated by Defender for Cloud and Defend
1818
- Each alert provides details of affected resources, issues, and remediation recommendations.
1919
- Defender for Cloud classifies alerts and prioritizes them by severity in the Defender for Cloud portal.
2020
- Alerts data is retained for 90 days.
21+
- An alert that was triggered on a resource will continue to be displayed for 90 days even if the resource was deleted during that time. This is because the alert
22+
might indicate a potential breach to your organization that needs to be further investigated.
2123
- Alerts can be exported to CSV format, or directly injected into Microsoft Sentinel.
2224
- Defender for Cloud leverages the [MITRE Attack Matrix](https://attack.mitre.org/matrices/enterprise/) to associate alerts with their perceived intent, helping formalize security domain knowledge.
2325

0 commit comments

Comments
 (0)