Skip to content

Commit cf2202e

Browse files
berlihiebmansheim
andauthored
Update articles/defender-for-cloud/alerts-overview.md
Co-authored-by: Ben Mansheim <[email protected]>
1 parent 9ccb502 commit cf2202e

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

articles/defender-for-cloud/alerts-overview.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,8 @@ Security alerts are the notifications generated by Defender for Cloud and Defend
1717
- Security alerts are triggered by advanced detections in Defender for Cloud, and are available when you enable [enhanced security features](enhanced-security-features-overview.md).
1818
- Each alert provides details of affected resources, issues, and remediation recommendations.
1919
- Defender for Cloud classifies alerts and prioritizes them by severity in the Defender for Cloud portal.
20-
- Alerts data is retained for 90 days.
21-
- An alert that was triggered on a resource will continue to be displayed for 90 days even if the resource was deleted during that time. This is because the alert
22-
might indicate a potential breach to your organization that needs to be further investigated.
20+
```suggestion
21+
- Alerts are displayed for 90 days, even if the resource related to the alert was deleted during that time. This is because the alert might indicate a potential breach to your organization that needs to be further investigated.
2322
- Alerts can be exported to CSV format, or directly injected into Microsoft Sentinel.
2423
- Defender for Cloud leverages the [MITRE Attack Matrix](https://attack.mitre.org/matrices/enterprise/) to associate alerts with their perceived intent, helping formalize security domain knowledge.
2524

0 commit comments

Comments
 (0)