Skip to content

Commit f00c51b

Browse files
committed
Fix tabs
1 parent 0fe0321 commit f00c51b

File tree

4 files changed

+23
-25
lines changed

4 files changed

+23
-25
lines changed

articles/sentinel/configure-data-connector.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -43,13 +43,9 @@ After you or someone in your organization installs the solution that includes th
4343
1. Select **Open connector page**.
4444

4545
#### [Defender portal](#tab/defender-portal)
46-
4746
:::image type="content" source="media/configure-data-connector/open-connector-page-option-defender-portal.png" alt-text="Screenshot of data connector details page in the Defender portal.":::
48-
4947
#### [Azure portal](#tab/azure-portal)
50-
5148
:::image type="content" source="media/configure-data-connector/open-connector-page-option.png" alt-text="Screenshot of data connector details page with open connector page button.":::
52-
5349
---
5450

5551
1. Review the **Prerequisites**. To configure the data connector, fulfill all the prerequisites.

articles/sentinel/hunts-custom-queries.md

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -24,16 +24,16 @@ Hunt for security threats across your organization's data sources with custom hu
2424

2525
In Microsoft Sentinel, create a custom hunting query from the **Hunting** > **Queries** tab.
2626

27-
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Threat management** select **Hunting**.<br> For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Threat management** > **Hunting**.
27+
1. For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Threat management** > **Hunting**. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **Threat management** select **Hunting**.
28+
2829
1. Select the **Queries** tab.
30+
2931
1. From the command bar, select **New query**.
3032

31-
# [Defender portal](#tab/defender-portal)
33+
### [Defender portal](#tab/defender-portal)
3234
:::image type="content" source="./media/hunts-custom-queries/save-query-defender.png" alt-text="Save query" lightbox="./media/hunts-custom-queries/save-query-defender.png":::
33-
34-
# [Azure portal](#tab/azure-portal)
35+
### [Azure portal](#tab/azure-portal)
3536
:::image type="content" source="./media/hunts-custom-queries/save-query.png" alt-text="Save query" lightbox="./media/hunts-custom-queries/save-query.png":::
36-
3737
---
3838

3939
1. Fill in all the blank fields.
@@ -46,23 +46,24 @@ In Microsoft Sentinel, create a custom hunting query from the **Hunting** > **Qu
4646

4747
:::image type="content" source="./media/hunting/mitre-attack-mapping-hunting.png" alt-text="New query" lightbox="./media/hunting/new-query.png":::
4848

49-
1. When your finished defining your query, select **Create**.
49+
1. When your finished defining your query, select **Create**.
5050

5151
## Clone an existing query
5252

5353
Clone a custom or built-in query and edit it as needed.
5454

5555
1. From the **Hunting** > **Queries** tab, select the hunting query you want to clone.
56+
5657
1. Select the ellipsis (...) in the line of the query you want to modify, and select **Clone**.
5758

58-
# [Defender portal](#tab/defender-portal)
59+
### [Defender portal](#tab/defender-portal)
5960
:::image type="content" source="./media/hunts-custom-queries/clone-hunting-query-defender.png" alt-text="Clone query" lightbox="./media/hunts-custom-queries/clone-hunting-query-defender.png":::
60-
61-
# [Azure portal](#tab/azure-portal)
61+
### [Azure portal](#tab/azure-portal)
6262
:::image type="content" source="./media/hunts-custom-queries/clone-hunting-query.png" alt-text="Clone query" lightbox="./media/hunts-custom-queries/clone-hunting-query.png":::
63-
6463
---
64+
6565
1. Edit the query and other fields as appropriate.
66+
6667
1. Select **Create**.
6768

6869
## Edit an existing custom query

articles/sentinel/search-jobs.md

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -29,16 +29,16 @@ Use a search job when you start an investigation to find specific events in logs
2929

3030
Go to **Search** in Microsoft Sentinel from the Azure portal or the Microsoft Defender portal to enter your search criteria. Depending on the size of the target dataset, search times vary. While most search jobs take a few minutes to complete, searches across massive data sets that run up to 24 hours are also supported.
3131

32-
1. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **General**, select **Search**. <br>For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Search**.
32+
1. For Microsoft Sentinel in the [Defender portal](https://security.microsoft.com/), select **Microsoft Sentinel** > **Search**. For Microsoft Sentinel in the [Azure portal](https://portal.azure.com), under **General**, select **Search**.
33+
3334
1. Select the **Table** menu and choose a table for your search.
35+
3436
1. In the **Search** box, enter a search term.
3537

36-
#### [Defender portal](#tab/defender-portal)
38+
### [Defender portal](#tab/defender-portal)
3739
:::image type="content" source="media/search-jobs/search-job-defender-portal.png" alt-text="Screenshot of search page with search criteria of administrator, time range last 90 days, and table selected." lightbox="media/search-jobs/search-job-defender-portal.png":::
38-
39-
#### [Azure portal](#tab/azure-portal)
40+
### [Azure portal](#tab/azure-portal)
4041
:::image type="content" source="media/search-jobs/search-job-criteria.png" alt-text="Screenshot of search page with search criteria of administrator, time range last 90 days, and table selected." lightbox="media/search-jobs/search-job-criteria.png":::
41-
4242
---
4343

4444
1. Select the **Start** to open the advanced Kusto Query Language (KQL) editor and preview of the results for a set time range.
@@ -50,10 +50,15 @@ Go to **Search** in Microsoft Sentinel from the Azure portal or the Microsoft De
5050
1. When you're satisfied with the query and the search results preview, select the ellipses **...** and toggle **Search job mode** on.
5151

5252
:::image type="content" source="media/search-jobs/search-job-advanced-kql-ellipsis.png" alt-text="Screenshot of KQL editor with revised search with ellipsis highlighted for Search job mode." lightbox="media/search-jobs/search-job-advanced-kql-ellipsis.png":::
53+
5354
1. Specify the search job date range using the **Time range** selector. Don't include a time range in your KQL query as it is ignored.
55+
5456
1. Resolve any KQL issues indicated by a squiggly red line in the editor.
57+
5558
1. When you're ready to start the search job, select **Search job**.
59+
5660
1. Enter a new table name to store the search job results.
61+
5762
1. Select **Run a search job**.
5863

5964
1. Wait for the notification **Search job is done** to view the results.

articles/sentinel/watchlists-create.md

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -44,14 +44,10 @@ If you didn't use a watchlist template to create your file,
4444

4545
1. Select **+ New**.
4646

47-
#### [Defender portal](#tab/defender-portal)
48-
47+
### [Defender portal](#tab/defender-portal)
4948
:::image type="content" source="./media/watchlists-create/sentinel-watchlist-new-defender.png" alt-text="Screenshot of add watchlist option on watchlist page." lightbox="./media/watchlists-create/sentinel-watchlist-new-defender.png":::
50-
51-
#### [Azure portal](#tab/azure-portal)
52-
49+
### [Azure portal](#tab/azure-portal)
5350
:::image type="content" source="./media/watchlists-create/sentinel-watchlist-new.png" alt-text="Screenshot of add watchlist option on watchlist page." lightbox="./media/watchlists-create/sentinel-watchlist-new.png":::
54-
5551
---
5652

5753
1. On the **General** page, provide the name, description, and alias for the watchlist.

0 commit comments

Comments
 (0)