Skip to content

Commit d9414b8

Browse files
Merge pull request #281221 from yelevin/yelevin/analytics-rules-conceptual
Error disclaimer
2 parents e24d8a0 + cde0759 commit d9414b8

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

articles/sentinel/customize-alert-details.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,10 +78,14 @@ Follow the procedure detailed below to use the alert details feature. These step
7878
| **ConfidenceScore** (Preview) | Integer, between **0**-**1** (inclusive) |
7979
| **ExtendedLinks** (Preview) | String |
8080
| **ProductComponentName** (Preview) | String |
81-
| **ProductName** (Preview) | String |
81+
| **ProductName** (Preview)<br>\* See note following this table | String |
8282
| **ProviderName** (Preview) | String |
8383
| **RemediationSteps** (Preview) | String |
8484

85+
> [!NOTE]
86+
>
87+
> If you onboarded Microsoft Sentinel to the unified security operations platform, **do not customize** the *ProductName* field for alerts from Microsoft sources. Doing so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
88+
8589
If you change your mind, or if you made a mistake, you can remove an alert detail by clicking the trash can icon next to the **Alert property/Value** pair, or delete the free text from the **Alert Name/Description Format** fields.
8690

8791
1. When you have finished customizing your alert details, if you're now creating the rule, continue to the next tab in the wizard. If you're editing an existing rule, select the **Review and create** tab. Once the rule validation is successful, select **Save**.

0 commit comments

Comments
 (0)