Skip to content

Commit cacd3fd

Browse files
committed
Edits
1 parent b30b940 commit cacd3fd

File tree

2 files changed

+8
-5
lines changed

2 files changed

+8
-5
lines changed

articles/defender-for-iot/organizations/how-to-manage-cloud-alerts.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -147,7 +147,7 @@ The file is generated, and you're prompted to save it locally.
147147

148148
## Remediate aggregated alerts
149149

150-
To reduce alert fatigue, multiple versions of the same alert with identical parameters are listed as one item in the Alerts page. As you investigate alerts, an aggregated alert is identified by the *Multiple violations* message that appears under the Source device IP. Use the **Violations** tab to investigate further and the **Take action** tab to remediate the alerts.
150+
To reduce alert fatigue, multiple versions of the same alert with identical parameters are listed as one item in the Alerts inventory. As you investigate alerts, an aggregated alert is identified by the *Multiple violations* message that appears under the Source device IP. Use the **Violations** tab to investigate further and the **Take action** tab to remediate the alerts.
151151

152152
1. On the **Alerts** page, select an alert in the grid to display more details in the pane on the right.
153153
1. For an Aggregated alert the *Multiple violations* message appears underneath the Source device IP address, and the **Violations** tab is displayed.

articles/defender-for-iot/organizations/how-to-view-alerts.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -179,14 +179,17 @@ For more information, see [Accelerating OT alert workflows](alerts.md#accelerati
179179

180180
## Remediate aggregated alerts
181181

182-
To reduce alert fatigue, multiple versions of the same alert with identical parameters are listed as one item in the Alerts page. Investigate the alerts and then remediate them using the Learn tab.
182+
To reduce alert fatigue, multiple versions of the same alert with identical parameters are listed as one item in the Alerts inventory. As you investigate alerts, an aggregated alert is identified by the *Multiple violations* message that appears under the Source device IP. Use the **Violations** tab to investigate further and the **Take action** tab to remediate the alerts.
183183

184184
1. Sign into your OT sensor console and select the **Alerts** page on the left.
185-
1. How do we know from the table that this is an aggregated alert?<!-- is there a violations column or -->
185+
1. For an Aggregated alert the *Multiple violations* message appears underneath the Source device IP address, and the **Violations** tab is displayed.
186+
187+
:::image type="content" source="media/how-to-manage-cloud-alerts/alert-details-aggregated.png" alt-text="Screenshot of the alerts detail pane showing the aggregated alerts message, the ViolationsCount and the Violations tab.":::
188+
<!-- change the image to one for an OT sensor -->
186189
1. Select the **Violations** tab.
187-
1. Export the data to a CSV file using the **Export** button. Open the file and examine the data.
190+
1. An inventory table displays the first 10 alerts from this aggregated alert group. Export the data to a CSV file using the **Export** button. Open the file and examine the data.
188191
1. Select the **Take action** tab. Follow the **Remediation steps**.
189-
1. Select the **Learn** button so that Defender for IoT learns that this doesn't need to create an alert item for this activity in the future.
192+
1. Select the **Learn** button, if appropriate, so that Defender for IoT learns that this network activity doesn't need to create an alert item in the future.
190193
<!-- go over this with the OT sensor and data that shows this feature and check this is correct -->
191194
## Next steps
192195

0 commit comments

Comments
 (0)