Skip to content

Commit 95fd737

Browse files
committed
Update metadata and known issues in hunting guide
Updated author, manager, and date metadata fields. Removed outdated known issue regarding the IdentityInfo table in Microsoft Sentinel, reflecting current schema availability.
1 parent 7bf2d70 commit 95fd737

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ ms.service: defender-xdr
66
ms.subservice: adv-hunting
77
f1.keywords:
88
- NOCSH
9-
ms.author: maccruz
10-
author: schmurky
9+
ms.author: pauloliveria
10+
author: poliveria
1111
ms.localizationpriority: medium
12-
manager: dansimp
12+
manager: orspodek
1313
audience: ITPro
1414
ms.collection:
1515
- m365-security
@@ -23,7 +23,7 @@ ms.topic: concept-article
2323
appliesto:
2424
- Microsoft Defender XDR
2525
- Microsoft Sentinel in the Microsoft Defender portal
26-
ms.date: 07/22/2025
26+
ms.date: 09/08/2025
2727
---
2828

2929
# Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
@@ -85,7 +85,6 @@ In the unified portal, in addition to viewing the schema column names and descri
8585

8686
## Known issues
8787

88-
- The `IdentityInfo table` from [Microsoft Sentinel](/azure/sentinel/ueba-reference#identityinfo-table) isn't available, as the `IdentityInfo` table remains as is in Defender XDR. Microsoft Sentinel features like analytics rules that query this table aren't impacted as they're querying the Log Analytics workspace directly.
8988
- The Microsoft Sentinel `SecurityAlert` table is replaced by `AlertInfo` and `AlertEvidence` tables, which both contain all the data on alerts. While SecurityAlert isn't available in the schema tab, you can still use it in queries using the advanced hunting editor. This provision is made so as not to break existing queries from Microsoft Sentinel that use this table.
9089
- Guided hunting mode and take actions capabilities are supported for Defender XDR data only.
9190
- Custom detections have the following limitations:

0 commit comments

Comments
 (0)