Skip to content

Commit 40dafa4

Browse files
committed
Timeline - Noa
1 parent 0150f29 commit 40dafa4

File tree

3 files changed

+2
-4
lines changed

3 files changed

+2
-4
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ While you can construct your [advanced hunting](advanced-hunting-overview.md) qu
3636
- [Export tables and charts](#export-tables-and-charts)
3737
- [Drill down to detailed entity information](#drill-down-from-query-results)
3838
- [Tweak your queries directly from the results](#tweak-your-queries-from-the-results)
39-
- [View timeline of events](#automatic-timeline-rendering)
39+
- [View timeline of events](#automatic-timeline-rendering-preview)
4040

4141
## View query results as a table or chart
4242

@@ -110,7 +110,6 @@ The line chart below clearly highlights time periods with more activity involvin
110110

111111
:::image type="content" source="/defender/media/line-chart-a.png" alt-text="The line chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="/defender/media/line-chart-a.png":::
112112

113-
114113
## Export tables and charts
115114

116115
After running a query, select **Export** to save the results to local file. Your chosen view determines how the results are exported:
@@ -158,7 +157,6 @@ Furthermore, for JSON and array fields, you can right-click and update the exist
158157

159158
:::image type="content" source="/defender/media/advanced-hunting-query-results-json-right.png" alt-text="Screenshot of options upon right-clicking an option for JSON and array fields" lightbox="/defender/media/advanced-hunting-query-results-json-right.png":::
160159

161-
162160
To quickly inspect a record in your query results, select the corresponding row to open the **Inspect record** panel. The panel provides the following information based on the selected record:
163161

164162
- **Assets**—Summarized view of the main assets (mailboxes, devices, and users) found in the record, enriched with available information, such as risk and exposure levels
@@ -201,7 +199,7 @@ You can do the same for your saved functions, queries, and custom detections in
201199

202200
By default, a timeline appears above the advanced hunting results that displays event counts over time. The timeline is automatically rendered based on the `Timestamp` or `timeGenerated` column in the query results. It automatically updates when you apply filters and can help you quickly identify abnormal behavior and trends and focus on interesting results.
203201

204-
:::image type="content" source="/defender/media/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="/defender/media/advanced-hunting-query-results-timeline.png":::
202+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="./media/advanced-hunting-query-results/advanced-hunting-query-results-timeline.png":::
205203

206204
You can select whether or not the timeline is displayed by default in the **Chart preferences** settings.
207205

97 KB
Loading
98.5 KB
Loading

0 commit comments

Comments
 (0)