Skip to content

Commit 9da55c1

Browse files
committed
changed formatting
1 parent 3779424 commit 9da55c1

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

articles/sentinel/soc-optimization/soc-optimization-reference.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -49,12 +49,14 @@ The following table lists the available types of data value SOC optimization rec
4949

5050
If a table is chosen for [UEBA](/azure/sentinel/enable-entity-behavior-analytics) or a [threat intelligence matching analytics rule](/azure/sentinel/use-matching-analytics-to-detect-threats), SOC optimization doesn't recommend any changes in ingestion.
5151

52-
### Unused columns
52+
### Unused columns (Preview)
5353

54-
SOC optimization also surfaces unused columns in your tables. If the columns have not been used in the last 30 days, we recommend that you stop data ingestion for these columns. This recommendation is available for the **ConditionalAccessPolicies** column in these tables:
54+
SOC optimization also surfaces unused columns in your tables. The following table lists the available types of columns available for SOC optimization recommendations:
5555

56-
- **SignInLogs**
57-
- **AADNonInteractiveUserSignInLogs**
56+
| Type of observation | Action |
57+
|---------|---------|
58+
| The **ConditionalAccessPolicies** column in the **SignInLogs** table or the **AADNonInteractiveUserSignInLogs** table is not in use. | Stop data ingestion for the column. |
59+
5860

5961
> [!IMPORTANT]
6062
> When making changes to ingestion plans, we recommend always ensuring that the limits of your ingestion plans are clear, and that the affected tables aren't ingested for compliance or other similar reasons.

0 commit comments

Comments
 (0)