Skip to content

Commit b4b146e

Browse files
committed
Update understand-threat-intelligence.md
1 parent 6fa88b8 commit b4b146e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/sentinel/understand-threat-intelligence.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -222,7 +222,7 @@ s` and `ThreatIntelObjects`. Microsoft Sentinel will ingest all threat intellige
222222
223223
### Threat intelligence lifecycle
224224

225-
Microsoft Sentinel ingests threat intelligence indicators into the threat intelligence tables in your Log Analytics workspace. To ensure data consistency and availability, Microsoft Sentinel reingests all data into the threat intelligence tables every seven days.
225+
Microsoft Sentinel stores threat intelligence data in your threat intelligence tables and automatically reingests all data every seven days to optimize query efficiency.
226226

227227
When an indicator is created, updated, or deleted, Microsoft Sentinel creates a new entry in the tables. Only the most current indicator appears on the management interface. Microsoft Sentinel deduplicates indicators based on the `Id` property (the `IndicatorId` property in the legacy `ThreatIntelligenceIndicator`) and chooses the indicator with the newest `TimeGenerated[UTC]`.
228228

0 commit comments

Comments
 (0)