You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-query-builder.md
+7-8Lines changed: 7 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,13 +56,12 @@ Selecting **All** includes data from all domains you currently have access to. N
56
56
57
57
You can choose from:
58
58
59
-
- All domains - to look through all available data in your query
60
-
- Endpoints - to look through endpoint data as provided by Microsoft Defender for Endpoint
61
-
- Email and collaboration - to look through email and collaboration apps data like SharePoint, OneDrive and others; users familiar with [Threat Explorer](/defender-office-365/threat-explorer-real-time-detections-about) can find the same data here
62
-
- Apps and identities - to look through application and identity data as provided by Microsoft Defender for Cloud Apps and Microsoft Defender for Identity; users familiar with [Activity log](/defender-cloud-apps/activity-filters) can find the same data here
63
-
- Cloud infrastructure - to look through cloud infrastructure data as provided by Microsoft Defender for Cloud
64
-
- Exposure management - to look through exposure management data as provided by Microsoft Security Exposure Management
65
-
59
+
- All domains - To look through all available data in your query.
60
+
- Endpoints - To look through endpoint data as provided by Microsoft Defender for Endpoint.
61
+
- Email and collaboration - To look through email and collaboration apps data like SharePoint, OneDrive and others; users familiar with [Threat Explorer](/defender-office-365/threat-explorer-real-time-detections-about) can find the same data here.
62
+
- Apps and identities - To look through application and identity data as provided by Microsoft Defender for Cloud Apps and Microsoft Defender for Identity; users familiar with [Activity log](/defender-cloud-apps/activity-filters) can find the same data here.
63
+
- Cloud infrastructure - To look through cloud infrastructure data as provided by Microsoft Defender for Cloud.
64
+
- Exposure management - To look through exposure management data as provided by Microsoft Security Exposure Management.
66
65
67
66
## Use basic filters
68
67
@@ -180,5 +179,5 @@ Then, add another condition, this time specifying the folder or **DeliveryLocati
180
179
181
180
-[Refine your query in guided mode](advanced-hunting-query-builder-details.md)
182
181
-[Work with query results in guided mode](advanced-hunting-query-builder-results.md)
183
-
-[Understand the schema](advanced-hunting-schema-tables.md)
182
+
-[Understand the schema](advanced-hunting-schema-tables.md)
0 commit comments