Skip to content

Commit ddbc51c

Browse files
authored
Update investigate-incidents.md
1 parent 096b235 commit ddbc51c

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed

articles/sentinel/investigate-incidents.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -233,13 +233,13 @@ If you prefer a visual, graphical representation of alerts, entities, and the co
233233

234234
The investigation graph provides you with:
235235

236-
- **Visual context from raw data**: The live, visual graph displays entity relationships extracted automatically from the raw data. This enables you to easily see connections across different data sources.
236+
| **Investigation content** | **Description** |
237+
|---------------------------|----------------------|
238+
| **Visual context from raw data** | The live, visual graph displays entity relationships extracted automatically from the raw data. This enables you to easily see connections across different data sources.|
239+
|**Full investigation scope discovery** | Expand your investigation scope using built-in exploration queries to surface the full scope of a breach.|
240+
| **Built-in investigation steps** | Use predefined exploration options to make sure you're asking the right questions in the face of a threat.|
237241

238-
- **Full investigation scope discovery**: Expand your investigation scope using built-in exploration queries to surface the full scope of a breach.
239-
240-
- **Built-in investigation steps**: Use predefined exploration options to make sure you're asking the right questions in the face of a threat.
241-
242-
To use the investigation graph:
242+
**To use the investigation graph**:
243243

244244
1. Select an incident, then select **Investigate**. This takes you to the investigation graph. The graph provides an illustrative map of the entities directly connected to the alert and each resource connected further.
245245

0 commit comments

Comments
 (0)