Skip to content

Commit 8196651

Browse files
Merge pull request #5818 from MicrosoftDocs/main
[AutoPublish] main to live - 12/02 07:34 PST | 12/02 21:04 IST
2 parents b7bfd43 + 797f72a commit 8196651

File tree

2 files changed

+59
-47
lines changed

2 files changed

+59
-47
lines changed

defender-xdr/advanced-hunting-link-to-incident.md

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ f1.keywords:
99
ms.author: pauloliveria
1010
author: poliveria
1111
ms.localizationpriority: medium
12-
manager: dansimp
12+
manager: orspodek
1313
audience: ITPro
1414
ms.collection:
1515
- m365-security
@@ -22,7 +22,7 @@ appliesto:
2222
- Microsoft Defender XDR
2323
- Microsoft Sentinel in the Microsoft Defender portal
2424
ms.topic: how-to
25-
ms.date: 03/28/2025
25+
ms.date: 12/02/2025
2626
---
2727

2828
# Link query results to an incident
@@ -32,7 +32,11 @@ ms.date: 03/28/2025
3232

3333

3434

35-
You can use the link to incident feature to add advanced hunting query results to a new or existing incident under investigation. This feature helps you easily capture records from advanced hunting activities, which enables you to create a richer timeline or context of events regarding an incident.
35+
Use the link to incident feature to add advanced hunting query results to a new or existing incident under investigation. This feature helps you easily capture records from advanced hunting activities, which enables you to create a richer timeline or context of events regarding an incident.
36+
37+
## Required permissions for linking incidents
38+
39+
To link query results to an incident, you need the same permissions required for managing custom detections. For more information, see [Create custom detection rules](custom-detection-rules.md#required-permissions-for-managing-custom-detections).
3640

3741
## Link results to new or existing incidents
3842

@@ -95,7 +99,7 @@ You can use the link to incident feature to add advanced hunting query results t
9599
7. Review the details you've provided in the Summary section.
96100
8. Select **Done**.
97101

98-
### View linked records in the incident
102+
## View linked records in the incident
99103

100104
You can select the generated link from the summary step of the wizard or select the incident name from the incident queue, to view the incident to which the events are linked.
101105

@@ -108,7 +112,7 @@ You can also select the event from the timeline view or from the query results v
108112

109113
:::image type="content" source="/defender/media/advanced-hunting-results-link8.png" alt-text="Screenshot of the incident page in the Microsoft Defender portal." lightbox="/defender/media/advanced-hunting-results-link8.png":::
110114

111-
### Filter for events added using advanced hunting
115+
## Filter for events added using advanced hunting
112116

113117
You can view which alerts were generated from advanced hunting by filtering incidents and alerts by **Manual** detection source.
114118

0 commit comments

Comments
 (0)