Skip to content

Commit 5044d73

Browse files
committed
updated text
1 parent 69ae931 commit 5044d73

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

defender-endpoint/threat-protection-reports.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -46,17 +46,17 @@ You can generate a PDF report of the summary, by selecting **Generate PDF repo
4646

4747
## Threat protection report
4848

49-
To gather data on Defender for Endpoint threat protection information, you can use the Microsoft Defender alerts queue or create advanced hunting queries. The following sections provide guidance on how to use these tools to find the information you need.
49+
To gather data on Defender for Endpoint threat protection information, you can use the Microsoft Defender portal's alerts queue or create advanced hunting queries. The following sections provide guidance on how to use these tools to find the information you need.
5050

5151
### Use the alert queue filter in the Microsoft Defender portal
5252

53-
You can use the Microsoft Defender portal alerts view, filtered against Defender for Endpoint, to see the current status of alerts for protected devices. For alert status, such as *unresolved*, you can filter against *New* and *In progress* items. [Learn more about the alerts queue](/defender-xdr/investigate-alerts).
53+
You can use the Microsoft Defender portal alerts view, using Defender for Endpoint as the **detection source**, to see the current status of alerts for protected devices. Use the **Status** filter to see *New*, *In progress*, and *Resolved* alerts. [Learn more about the alerts queue](/defender-xdr/investigate-alerts).
5454

5555
### Use advanced hunting queries
5656

57-
You can also use advanced hunting queries to find Defender for Endpoint threat protection information. [Learn more about advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). See the following section for a sample advanced hunting query that shows endpoint-related threat protection details.
57+
You can also use advanced hunting queries to find Defender for Endpoint threat protection information. [Learn more about advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). The following sample advanced hunting queries show alert-related information.
5858

59-
#### Alert status
59+
#### Alert information by severity, detection source, and category
6060

6161
```kusto
6262
// Severity
@@ -78,7 +78,7 @@ AlertInfo
7878
| render columnchart
7979
```
8080

81-
#### Alert trend
81+
#### Alert trends by severity, detection source, and category
8282

8383
```kusto
8484
// Severity

0 commit comments

Comments
 (0)