Skip to content

Commit 66db898

Browse files
Merge pull request #2602 from yelevin/yelevin/rename-link-to-move
Change "Link/unlink alerts" to "Move alerts"
2 parents 2099c17 + bf01f82 commit 66db898

12 files changed

+29
-24
lines changed

.openpublishing.redirection.defender-xdr.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -131,6 +131,11 @@
131131
"redirect_url": "/defender-xdr/entity-page-device",
132132
"redirect_document_id": true
133133
},
134+
{
135+
"source_path": "defender-xdr/unlink-alert-from-incident.md",
136+
"redirect_url": "/defender-xdr/move-alert-to-another-incident",
137+
"redirect_document_id": true
138+
},
134139
{
135140
"source_path": "defender-xdr/unified-secops-platform/defender-xdr-portal.md",
136141
"redirect_url": "/defender-xdr/",

defender-xdr/TOC.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -90,8 +90,8 @@
9090
items:
9191
- name: Incidents
9292
href: investigate-incidents.md
93-
- name: Unlink alerts from incidents
94-
href: unlink-alert-from-incident.md
93+
- name: Move alerts to another incident
94+
href: move-alert-to-another-incident.md
9595
- name: Alerts
9696
href: investigate-alerts.md
9797
- name: Entity pages

defender-xdr/alerts-incidents-correlation.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -41,11 +41,11 @@ The criteria used by the Defender portal to correlate alerts together in a singl
4141

4242
While Microsoft Defender already uses advanced correlation mechanisms, you might want to decide differently whether a given alert belongs with a particular incident or not. In such a case, you can unlink an alert from one incident and link it to another. Every alert must belong to an incident, so you can either link the alert to another existing incident, or to a new incident that you create on the spot.
4343

44-
For instructions, see [Link alerts to another incident in the Microsoft Defender portal](unlink-alert-from-incident.md).
44+
For more information on moving an alert from one incident to another, see [Move alerts from one incident to another in the Microsoft Defender portal](move-alert-to-another-incident.md).
4545

4646
## Incident correlation and merging
4747

48-
The Defender portal's correlation activities don't stop when incidents are created. Defender continues to detect commonalities and relationships between incidents, and between alerts across incidents. When two or more incidents are determined to be sufficiently alike, Defender merges the incidents into a single incident.
48+
The Defender portal's correlation activities don't stop when incidents are created. Defender continues to detect commonalities and relationships between incidents and alerts across incidents. When two or more incidents are determined to be sufficiently alike, Defender merges the incidents into a single incident.
4949

5050
### Criteria for merging incidents
5151

146 KB
Loading
19.3 KB
Loading
55.4 KB
Loading
16.5 KB
Loading
Binary file not shown.
Binary file not shown.
Binary file not shown.

0 commit comments

Comments
 (0)