Skip to content

Commit 0e49de8

Browse files
committed
added context
1 parent e08c0b9 commit 0e49de8

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

defender-xdr/investigate-incidents.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,11 @@ You can view an incident's details on the right pane of an incident page. The in
125125

126126
:::image type="content" source="/defender/media/investigate-incidents/incident-desc-small.png" alt-text="An example of incident details where the description is highlighted." lightbox="/defender/media/investigate-incidents/incident-desc.png":::
127127

128+
The incident description provides a brief overview of the incident. In some cases, the first alert in the incident is used as the incident description. In this case, the description is only shown in the portal and not stored in the activity log, advanced hunting tables, or the Microsoft Sentinel in Azure portal.
129+
130+
> [!TIP]
131+
> Microsoft Sentinel customers can also view the same incident description in the Azure portal by setting the incident description through API or automation.
132+
128133
## Alerts
129134

130135
On the **Alerts** tab, you can view the alert queue for alerts related to the incident and other information about them like the following:

0 commit comments

Comments
 (0)