Skip to content

Commit b0cc032

Browse files
authored
Update metadata and notes in investigate-alerts.md
1 parent 6375a5f commit b0cc032

File tree

1 file changed

+11
-16
lines changed

1 file changed

+11
-16
lines changed

defender-xdr/investigate-alerts.md

Lines changed: 11 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -3,26 +3,23 @@ title: Investigate alerts in Microsoft Defender XDR
33
description: Investigate alerts seen across devices, users, and mailboxes.
44
keywords: incidents, alerts, investigate, analyze, response, correlation, attack, machines, devices, users, identities, identity, mailbox, email, 365, microsoft, m365
55
ms.service: defender-xdr
6-
ms.mktglfcycl: deploy
7-
ms.sitesec: library
8-
ms.pagetype: security
96
f1.keywords:
10-
- NOCSH
7+
- NOCSH
118
ms.author: diannegali
129
author: diannegali
1310
ms.localizationpriority: medium
1411
manager: deniseb
1512
audience: ITPro
1613
ms.collection:
17-
- m365-security
18-
- m365initiative-m365-defender
19-
- tier1
14+
- m365-security
15+
- m365initiative-m365-defender
16+
- tier1
2017
ms.custom: admindeeplinkDEFENDER
2118
ms.topic: conceptual
2219
search.appverid:
23-
- MOE150
24-
- met150
25-
ms.date: 07/18/2024
20+
- MOE150
21+
- met150
22+
ms.date: 01/16/2025
2623
---
2724

2825
# Investigate alerts in Microsoft Defender XDR
@@ -117,7 +114,6 @@ Throughout an alert page, you can select the ellipses (**...**) beside any entit
117114
Microsoft Defender XDR alerts come from solutions like Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, the app governance add-on for Microsoft Defender for Cloud Apps, Microsoft Entra ID Protection, and Microsoft Data Loss Prevention. You might notice alerts with prepended characters in the alert. The following table provides guidance to help you understand the mapping of alert sources based on the prepended character on the alert.
118115

119116
> [!NOTE]
120-
>
121117
> - The prepended GUIDs are specific only to unified experiences such as unified alerts queue, unified alerts page, unified investigation, and unified incident.
122118
> - The prepended character does not change the GUID of the alert. The only change to the GUID is the prepended component.
123119
@@ -188,12 +184,11 @@ The **Manage alert** pane allows you to view or specify:
188184
- A comment on the alert.
189185

190186
> [!NOTE]
191-
> Around August 29th, 2022, previously supported alert determination values ('Apt' and 'SecurityPersonnel') will be deprecated and no longer available via the API.
192-
193-
> [!NOTE]
194-
> One way of managing alerts it through the use of tags. The tagging capability for Microsoft Defender for Office 365 is incrementally being rolled out and is currently in preview.
187+
> - In August 2022, previously supported alert determination values (`Apt` and `SecurityPersonnel`) were deprecated and are no longer available via the API.
188+
>
189+
> - One way of managing alerts it through the use of tags. The tagging capability for Microsoft Defender for Office 365 is currently in preview, rolling out incrementally.
195190
>
196-
> Currently, modified tag names are only applied to alerts created *after* the update. Alerts that were generated before the modification will not reflect the updated tag name.
191+
> - Currently, modified tag names are only applied to alerts created *after* the update. Alerts that were generated before the modification don't reflect the updated tag name.
197192
198193
To manage a *set of alerts similar to a specific alert*, select **View similar alerts** in the **INSIGHT** box in the summary details section of the alert page.
199194

0 commit comments

Comments
 (0)