Skip to content

Commit b259a7b

Browse files
Merge pull request #3808 from MicrosoftDocs/main
[AutoPublish] main to live - 05/16 10:30 PDT | 05/16 23:00 IST
2 parents 8e355ce + 68087fd commit b259a7b

File tree

1 file changed

+7
-2
lines changed

1 file changed

+7
-2
lines changed

defender-xdr/advanced-hunting-overview.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -65,8 +65,13 @@ Also, your access to endpoint data is determined by role-based access control (R
6565
## Data freshness and update frequency
6666
Advanced hunting data can be categorized into two distinct types, each consolidated differently.
6767

68-
- **Event or activity data**—populates tables about alerts, security events, system events, and routine assessments. Advanced hunting receives this data almost immediately after the sensors that collect them successfully transmit them to the corresponding cloud services. For example, you can query event data from healthy sensors on workstations or domain controllers almost immediately after they are available on Microsoft Defender for Endpoint and Microsoft Defender for Identity.
69-
- **Entity data**—populates tables with information about users and devices. This data comes from both relatively static data sources and dynamic sources, such as Active Directory entries and event logs. To provide fresh data, tables are updated with any new information every 15 minutes, adding rows that might not be fully populated. Every 24 hours, data is consolidated to insert a record that contains the latest, most comprehensive data set about each entity.
68+
### **Event or activity data**
69+
Event or activity data populates tables about alerts, security events, system events, and routine assessments. Advanced hunting receives this data almost immediately after the sensors that collect them successfully transmit them to the corresponding cloud services. For example, you can query event data from healthy sensors on workstations or domain controllers almost immediately after they are available on Microsoft Defender for Endpoint and Microsoft Defender for Identity.
70+
71+
To collect even more event properties, you have the option of turning on [aggregated reporting](/defender-endpoint/aggregated-reporting).
72+
73+
### **Entity data**
74+
Entity data populates tables with information about users and devices. This data comes from both relatively static data sources and dynamic sources, such as Active Directory entries and event logs. To provide fresh data, tables are updated with any new information every 15 minutes, adding rows that might not be fully populated. Every 24 hours, data is consolidated to insert a record that contains the latest, most comprehensive data set about each entity.
7075

7176

7277
## Time zone

0 commit comments

Comments
 (0)