Skip to content

Commit fd93ddb

Browse files
Merge pull request #272156 from batamig/patch-414
Sentinel analytic rule name clarification
2 parents 3c29504 + 43e2341 commit fd93ddb

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

articles/sentinel/create-manage-use-automation-rules.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,8 @@ Use the options in the **Conditions** area to define conditions for your automat
9292

9393
- Rules you create for when an alert is created support only the **If Analytic rule name** property in your condition. Select whether you want the rule to be inclusive (*Contains*) or exclusive (*Does not contain*), and then select the analytic rule name from the drop-down list.
9494

95+
Analytic rule name values include only analytics rules, and don't include other types of rules, such as threat intelligence or anomaly rules.
96+
9597
- Rules you create for when an incident is created or updated support a large variety of conditions, depending on your environment. These options start with whether your workspace is onboarded to the unified security operations platform:
9698

9799
#### [Onboarded workspaces](#tab/onboarded)

0 commit comments

Comments
 (0)