Skip to content

Commit e997143

Browse files
committed
Error disclaimer
1 parent ae17b7d commit e997143

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

articles/sentinel/customize-alert-details.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,10 +78,14 @@ Follow the procedure detailed below to use the alert details feature. These step
7878
| **ConfidenceScore** (Preview) | Integer, between **0**-**1** (inclusive) |
7979
| **ExtendedLinks** (Preview) | String |
8080
| **ProductComponentName** (Preview) | String |
81-
| **ProductName** (Preview) | String |
81+
| **ProductName** (Preview)<br>\* See note following this table | String |
8282
| **ProviderName** (Preview) | String |
8383
| **RemediationSteps** (Preview) | String |
8484

85+
> [!NOTE]
86+
>
87+
> If you onboarded Microsoft Sentinel to the unified security operations platform, **do not customize** the *ProductName* field for alerts from Microsoft sources. Doing so will result in these alerts being dropped from Microsoft Defender XDR and no incident being created.
88+
8589
If you change your mind, or if you made a mistake, you can remove an alert detail by clicking the trash can icon next to the **Alert property/Value** pair, or delete the free text from the **Alert Name/Description Format** fields.
8690

8791
1. When you have finished customizing your alert details, if you're now creating the rule, continue to the next tab in the wizard. If you're editing an existing rule, select the **Review and create** tab. Once the rule validation is successful, select **Save**.

0 commit comments

Comments
 (0)