You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/create-nrt-rules.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,7 +20,7 @@ For the time being, these templates have limited application as outlined below,
20
20
21
21
## View near-real-time (NRT) rules
22
22
23
-
# [Azure portal](#tab/azure)
23
+
# [Azure portal](#tab/azure-portal)
24
24
25
25
1. From the **Configuration** section of the Microsoft Sentinel navigation menu, select **Analytics**.
26
26
@@ -30,7 +30,7 @@ For the time being, these templates have limited application as outlined below,
30
30
31
31
1. From the resulting list, select **NRT**. Then select **Apply**.
32
32
33
-
# [Defender portal](#tab/defender)
33
+
# [Defender portal](#tab/defender-portal)
34
34
35
35
1. From the Microsoft Defender navigation menu, expand **Microsoft Sentinel**, then **Configuration**. Select **Analytics**.
36
36
@@ -46,15 +46,15 @@ For the time being, these templates have limited application as outlined below,
46
46
47
47
You create NRT rules the same way you create regular [scheduled-query analytics rules](detect-threats-custom.md):
48
48
49
-
# [Azure portal](#tab/azure)
49
+
# [Azure portal](#tab/azure-portal)
50
50
51
51
1. From the **Configuration** section of the Microsoft Sentinel navigation menu, select **Analytics**.
52
52
53
53
1. In the action bar at the top, select **+Create** and select **NRT query rule**. This opens the **Analytics rule wizard**.
54
54
55
55
:::image type="content" source="media/create-nrt-rules/create-nrt-rule.png" alt-text="Screenshot shows how to create a new NRT rule." lightbox="media/create-nrt-rules/create-nrt-rule.png":::
56
56
57
-
# [Defender portal](#tab/defender)
57
+
# [Defender portal](#tab/defender-portal)
58
58
59
59
1. From the Microsoft Defender navigation menu, expand **Microsoft Sentinel**, then **Configuration**. Select **Analytics**.
0 commit comments