Skip to content

Commit 3aa0da5

Browse files
authored
Update advanced-hunting-microsoft-defender.md
Add to "known Issues": When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.
1 parent 8f201a0 commit 3aa0da5

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,7 @@ In the unified portal, in addition to viewing the schema column names and descri
9393
- Near real-time detection frequency isn't available for detections that include Microsoft Sentinel data.
9494
- Custom functions that were created and saved in Microsoft Sentinel aren't supported.
9595
- Defining entities from Sentinel data isn't yet supported in custom detections.
96+
- When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.
9697
- Bookmarks aren't supported in the advanced hunting experience. They're supported in the **Microsoft Sentinel > Threat management > Hunting** feature. Alternatively, you can use the [Link to incident](advanced-hunting-defender-results.md#link-query-results-to-an-incident) feature to link query results to new or existing incidents.
9798
- If you're streaming Defender XDR tables to Log Analytics, there might be a difference between the`Timestamp` and `TimeGenerated` columns. In case the data arrives to Log Analytics after 48 hours, it's being overridden upon ingestion to `now()`. Therefore, to get the actual time the event happened, we recommend relying on the `Timestamp` column.
9899
- When prompting [Security Copilot](advanced-hunting-security-copilot.md) for advanced hunting queries, you might find that not all Microsoft Sentinel tables are currently supported. However, support for these tables can be expected in the future.

0 commit comments

Comments
 (0)