Skip to content

Commit fed644e

Browse files
committed
further sanity + metdata
1 parent b5f2775 commit fed644e

File tree

6 files changed

+18
-1
lines changed

6 files changed

+18
-1
lines changed

articles/sentinel/surface-custom-details-in-alerts.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: yelevin
55
ms.topic: how-to
66
ms.date: 04/26/2022
77
ms.author: yelevin
8+
appliesto:
9+
- Microsoft Sentinel in the Azure portal
10+
- Microsoft Sentinel in the Microsoft Defender portal
11+
ms.collection: usx-security
812
---
913

1014
# Surface custom event details in alerts in Microsoft Sentinel

articles/sentinel/ueba-reference.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: yelevin
55
ms.topic: reference
66
ms.date: 06/28/2022
77
ms.author: yelevin
8+
appliesto:
9+
- Microsoft Sentinel in the Azure portal
10+
- Microsoft Sentinel in the Microsoft Defender portal
11+
ms.collection: usx-security
812
---
913

1014
# Microsoft Sentinel UEBA reference

articles/sentinel/watchlists-create.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,8 @@ Local file uploads are currently limited to files of up to 3.8 MB in size. A fil
2323

2424
> [!IMPORTANT]
2525
> The features for watchlist templates and the ability to create a watchlist from a file in Azure Storage are currently in **PREVIEW**. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
26-
>
26+
>
27+
> [!INCLUDE [unified-soc-preview-without-alert](includes/unified-soc-preview-without-alert.md)]
2728
2829
## Upload a watchlist from a local folder
2930

articles/sentinel/watchlists-manage.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,8 @@ ms.collection: usx-security
1616

1717
We recommend you edit an existing watchlist instead of deleting and recreating a watchlist. Log analytics has a five-minute SLA for data ingestion. If you delete and recreate a watchlist, you might see both the deleted and recreated entries in Log Analytics during this five-minute window. If you see these duplicate entries in Log Analytics for a longer period of time, submit a support ticket.
1818

19+
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
20+
1921
## Edit a watchlist item
2022

2123
Edit a watchlist to edit or add an item to the watchlist.

articles/sentinel/watchlists-queries.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,8 @@ Query data in any table against data from a watchlist by treating the watchlist
1818

1919
For optimal query performance, use **SearchKey** as the key for joins in your queries.
2020

21+
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
22+
2123
## Build queries with watchlists
2224

2325
To use a watchlist in search query, write a Kusto query that uses the _GetWatchlist('watchlist-name') function and uses **SearchKey** as the key for your join.

articles/sentinel/work-with-anomaly-rules.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: yelevin
55
ms.topic: how-to
66
ms.date: 03/17/2024
77
ms.author: yelevin
8+
appliesto:
9+
- Microsoft Sentinel in the Azure portal
10+
- Microsoft Sentinel in the Microsoft Defender portal
11+
ms.collection: usx-security
812
---
913

1014
# Work with anomaly detection analytics rules in Microsoft Sentinel

0 commit comments

Comments
 (0)