Skip to content

Commit 95ba5bb

Browse files
committed
Update advanced-hunting-overview.md
1 parent e1c6613 commit 95ba5bb

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-xdr/advanced-hunting-overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ Advanced hunting data can be categorized into two distinct types, each consolida
6868
### **Event or activity data**
6969
Event or activity data populates tables about alerts, security events, system events, and routine assessments. Advanced hunting receives this data almost immediately after the sensors that collect them successfully transmit them to the corresponding cloud services. For example, you can query event data from healthy sensors on workstations or domain controllers almost immediately after they are available on Microsoft Defender for Endpoint and Microsoft Defender for Identity.
7070

71-
To collect even more event properties, you have the option of turning on [aggregated reporting](/defender-endpoint/aggregated-reporting.md).
71+
To collect even more event properties, you have the option of turning on [aggregated reporting](/defender-endpoint/aggregated-reporting).
7272

7373
### **Entity data**
7474
Entity data populates tables with information about users and devices. This data comes from both relatively static data sources and dynamic sources, such as Active Directory entries and event logs. To provide fresh data, tables are updated with any new information every 15 minutes, adding rows that might not be fully populated. Every 24 hours, data is consolidated to insert a record that contains the latest, most comprehensive data set about each entity.

0 commit comments

Comments
 (0)