Skip to content

Commit 63c1ed6

Browse files
authored
Update investigate-alerts.md
1 parent da064f3 commit 63c1ed6

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

defender-xdr/investigate-alerts.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -298,9 +298,7 @@ Create alert tuning rules from the Microsoft Defender XDR **Settings** area or f
298298
> The **alert title (Name)** is based on the **alert type (IoaDefinitionId)**, which decides the alert title. Two alerts that have the same alert type can change to a different alert title.
299299
> The *Hide alert* feature is only available in Defender for Endpoint alerts.
300300
301-
<!--what does this mean?-->
302-
303-
<!--i don't see how to validate this?>
301+
<!--
304302
After creating your alert tuning rule from an alert details page, in the **Successful rule creation** page that appears, add any of the alert-related IOCs as indicators to an *allow list* to prevent them from being blocked in the future. IOCs that are configured as part of the alert tuning rule are selected by default. For example:
305303
306304
1. Add a file to the **Select evidence (IOC) to allow** list. By default, the file that triggered the alert is already selected.

0 commit comments

Comments
 (0)