Skip to content

Commit cc4a33a

Browse files
authored
Update customize-alert-details.md
1 parent f293c30 commit cc4a33a

File tree

1 file changed

+15
-4
lines changed

1 file changed

+15
-4
lines changed

articles/sentinel/customize-alert-details.md

Lines changed: 15 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -81,14 +81,25 @@ Follow the procedure detailed below to use the alert details feature. These step
8181
| **ConfidenceLevel** (Preview) | One of the following values: <br>- **Low**<br>- **High**<br>- **Unknown** |
8282
| **ConfidenceScore** (Preview) | Integer, between **0**-**1** (inclusive) |
8383
| **ExtendedLinks** (Preview) | String |
84-
| **ProductComponentName** (Preview) | String |
85-
| **ProductName** (Preview)<br>\* See note following this table | String |
86-
| **ProviderName** (Preview) | String |
84+
| **ProductComponentName** (Preview)<br>\* See Caution notes following this table | String |
85+
| **ProductName** (Preview)<br>\* See Caution notes following this table | String |
86+
| **ProviderName** (Preview)<br>\* See Caution notes following this table | String |
8787
| **RemediationSteps** (Preview) | String |
8888

89-
> [!NOTE]
89+
> [!CAUTION]
90+
>
91+
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, **do not customize** the following properties for alerts from Microsoft sources:
92+
> - *ProductName* field
93+
> - *ProductComponentName* field
94+
> - *ProviderName* field
95+
>
96+
> Attempting to do so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
97+
98+
> [!CAUTION]
9099
>
91100
> If you onboarded Microsoft Sentinel to the Microsoft Defender portal, **do not customize** the *ProductName* field for alerts from Microsoft sources. Doing so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
101+
>
102+
> Also, you will not be able to customize the *ProductComponentName* and *ProviderName* fields.
92103
93104
If you change your mind, or if you made a mistake, you can remove an alert detail by clicking the trash can icon next to the **Alert property/Value** pair, or delete the free text from the **Alert Name/Description Format** fields.
94105

0 commit comments

Comments
 (0)