Skip to content

Commit 81b5591

Browse files
committed
wi-502580-batch-2b-defender-xdr-image-reorg
1 parent 2f65488 commit 81b5591

13 files changed

+12
-12
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ AlertInfo
7878
| render columnchart
7979
```
8080

81-
:::image type="content" source="/defender/media/advanced-hunting-column-chart-new.png" alt-text="An example of a chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-column-chart-new.png":::
81+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-column-chart-new.png" alt-text="An example of a chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="./media/advanced-hunting-query-results/advanced-hunting-column-chart-new.png":::
8282

8383
#### Phishing emails across top ten sender domains
8484

@@ -93,7 +93,7 @@ EmailEvents
9393

9494
Use the pie chart view to effectively show distribution across the top domains:
9595

96-
:::image type="content" source="/defender/media/advanced-hunting-pie-chart-new.png" alt-text="The pie chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-pie-chart-new.png":::
96+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-pie-chart-new.png" alt-text="The pie chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="./media/advanced-hunting-query-results/advanced-hunting-pie-chart-new.png":::
9797

9898

9999
#### File activities over time
@@ -108,7 +108,7 @@ CloudAppEvents
108108

109109
The line chart below clearly highlights time periods with more activity involving `invoice.doc`:
110110

111-
:::image type="content" source="/defender/media/line-chart-a.png" alt-text="The line chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="/defender/media/line-chart-a.png":::
111+
:::image type="content" source="./media/advanced-hunting-query-results/line-chart-a.png" alt-text="The line chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="./media/advanced-hunting-query-results/line-chart-a.png":::
112112

113113
## Export tables and charts
114114

@@ -121,23 +121,23 @@ After running a query, select **Export** to save the results to local file. Your
121121

122122
After running a query, select **Filter** to narrow down the results.
123123

124-
:::image type="content" source="/defender/media/add-filter1.png" alt-text="Screenshot of filters in advanced hunting." lightbox="/defender/media/add-filter1.png":::
124+
:::image type="content" source="./media/advanced-hunting-query-results/add-filter1.png" alt-text="Screenshot of filters in advanced hunting." lightbox="./media/advanced-hunting-query-results/add-filter1.png":::
125125

126126
To add a filter, select the data you want to filter for by selecting one or more of the check boxes. Then select **Add**.
127127

128-
:::image type="content" source="/defender/media/add-filter2.png" alt-text="Screenshot of filters dropdown in advanced hunting." lightbox="/defender/media/add-filter2.png":::
128+
:::image type="content" source="./media/advanced-hunting-query-results/add-filter2.png" alt-text="Screenshot of filters dropdown in advanced hunting." lightbox="./media/advanced-hunting-query-results/add-filter2.png":::
129129

130130
You can narrow the results down even further to specific data by selecting the newly added filter.
131131

132-
:::image type="content" source="/defender/media/add-filter3.png" alt-text="Screenshot of new filter pill in advanced hunting." lightbox="/defender/media/add-filter3.png":::
132+
:::image type="content" source="./media/advanced-hunting-query-results/add-filter3.png" alt-text="Screenshot of new filter pill in advanced hunting." lightbox="./media/advanced-hunting-query-results/add-filter3.png":::
133133

134134
This opens a dropdown showing the possible filters you can use further. Select one or more of the check boxes, then select **Apply**.
135135

136-
:::image type="content" source="/defender/media/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="/defender/media/add-filter4.png":::
136+
:::image type="content" source="./media/advanced-hunting-query-results/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="./media/advanced-hunting-query-results/add-filter4.png":::
137137

138138
Confirm that you have added the filters that you wanted by checking the Filters section.
139139

140-
:::image type="content" source="/defender/media/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="/defender/media/add-filter5.png":::
140+
:::image type="content" source="./media/advanced-hunting-query-results/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="./media/advanced-hunting-query-results/add-filter5.png":::
141141

142142
## Drill down from query results
143143

@@ -147,22 +147,22 @@ You can also explore the results in-line with the following features:
147147
- Where applicable, expand details for results that are in JSON and array formats by selecting the dropdown arrow at the left of applicable column names for added readability
148148
- Open the side pane to see a record's details (concurrent with expanded rows)
149149

150-
:::image type="content" source="/defender/media/advanced-hunting-query-results-expand.png" alt-text="Screenshot of expanding results to drill down" lightbox="/defender/media/advanced-hunting-query-results-expand.png":::
150+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-query-results-expand.png" alt-text="Screenshot of expanding results to drill down" lightbox="./media/advanced-hunting-query-results/advanced-hunting-query-results-expand.png":::
151151

152152
You can also right-click on any result value in a row so that you can use it to add more filters to the existing query or copy the value for use in further investigation.
153153

154-
:::image type="content" source="/defender/media/advanced-hunting-query-results-rightclick.png" alt-text="Screenshot of options upon right-clicking an option" lightbox="/defender/media/advanced-hunting-query-results-rightclick.png":::
154+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-query-results-rightclick.png" alt-text="Screenshot of options upon right-clicking an option" lightbox="./media/advanced-hunting-query-results/advanced-hunting-query-results-rightclick.png":::
155155

156156
Furthermore, for JSON and array fields, you can right-click and update the existing query to include or exclude the field, or to extend the field to a new column.
157157

158-
:::image type="content" source="/defender/media/advanced-hunting-query-results-json-right.png" alt-text="Screenshot of options upon right-clicking an option for JSON and array fields" lightbox="/defender/media/advanced-hunting-query-results-json-right.png":::
158+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-query-results-json-right.png" alt-text="Screenshot of options upon right-clicking an option for JSON and array fields" lightbox="./media/advanced-hunting-query-results/advanced-hunting-query-results-json-right.png":::
159159

160160
To quickly inspect a record in your query results, select the corresponding row to open the **Inspect record** panel. The panel provides the following information based on the selected record:
161161

162162
- **Assets**—Summarized view of the main assets (mailboxes, devices, and users) found in the record, enriched with available information, such as risk and exposure levels
163163
- **All details**—All the values from the columns in the record
164164

165-
:::image type="content" source="/defender/media/results-inspect-record.png" alt-text="The selected record with panel for inspecting the record in the Microsoft Defender portal" lightbox="/defender/media/results-inspect-record.png":::
165+
:::image type="content" source="./media/advanced-hunting-query-results/results-inspect-record.png" alt-text="The selected record with panel for inspecting the record in the Microsoft Defender portal" lightbox="./media/advanced-hunting-query-results/results-inspect-record.png":::
166166

167167
To view more information about a specific entity in your query results, such as a machine, file, user, IP address, or URL, select the entity identifier to open a detailed profile page for that entity.
168168

defender/media/add-filter1.png renamed to defender-xdr/media/advanced-hunting-query-results/add-filter1.png

File renamed without changes.

defender/media/add-filter2.png renamed to defender-xdr/media/advanced-hunting-query-results/add-filter2.png

File renamed without changes.

defender/media/add-filter3.png renamed to defender-xdr/media/advanced-hunting-query-results/add-filter3.png

File renamed without changes.

defender/media/add-filter4.png renamed to defender-xdr/media/advanced-hunting-query-results/add-filter4.png

File renamed without changes.

defender/media/add-filter5.png renamed to defender-xdr/media/advanced-hunting-query-results/add-filter5.png

File renamed without changes.

defender/media/advanced-hunting-column-chart-new.png renamed to defender-xdr/media/advanced-hunting-query-results/advanced-hunting-column-chart-new.png

File renamed without changes.

defender/media/advanced-hunting-pie-chart-new.png renamed to defender-xdr/media/advanced-hunting-query-results/advanced-hunting-pie-chart-new.png

File renamed without changes.

defender/media/advanced-hunting-query-results-expand.png renamed to defender-xdr/media/advanced-hunting-query-results/advanced-hunting-query-results-expand.png

File renamed without changes.

defender/media/advanced-hunting-query-results-json-right.png renamed to defender-xdr/media/advanced-hunting-query-results/advanced-hunting-query-results-json-right.png

File renamed without changes.

0 commit comments

Comments
 (0)