Skip to content

Commit af34ac8

Browse files
committed
edit
1 parent afabbb8 commit af34ac8

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

defender-xdr/advanced-hunting-defender-use-custom-rules.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -115,7 +115,9 @@ For analytics rules that apply to data ingested through the connected Microsoft
115115

116116
The **Analytics rule wizard** appears. Fill up the required details as described in [Analytics rule wizard—General tab](/azure/sentinel/detect-threats-custom#analytics-rule-wizardgeneral-tab).
117117

118-
You can also create custom detection rules that query data from both Microsoft Sentinel and Defender XDR tables. Select **Manage rules > Create custom detection**. Read [Create and manage custom detection rules](custom-detection-rules.md) for more information. In custom detection rule creation, you can only query data from analytics log type tables, otherwise the rule creation won't proceed.
118+
You can also create custom detection rules that query data from both Microsoft Sentinel and Defender XDR tables. Select **Manage rules > Create custom detection**. Read [Create and manage custom detection rules](custom-detection-rules.md) for more information.
119+
120+
In custom detection rule creation, you can only query data ingested as analytics logs (that is, not as basic logs or auxiliary logs, see [log management plans](/azure/sentinel/log-plans#log-management-plans) to check the different tiers) otherwise the rule creation won't proceed.
119121

120122
If your Defender XDR data is ingested into Microsoft Sentinel, you have the option to choose between **Create custom detection** and **Create analytics rule**.
121123

0 commit comments

Comments
 (0)