Skip to content

Commit c4f9509

Browse files
committed
Reorg Sentinel-related
1 parent bbcbbd5 commit c4f9509

File tree

4 files changed

+18
-11
lines changed

4 files changed

+18
-11
lines changed

defender-xdr/TOC.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -222,8 +222,14 @@
222222
href: advanced-hunting-modes.md
223223
- name: Generate KQL queries with Security Copilot
224224
href: advanced-hunting-security-copilot.md
225-
- name: Advanced hunting in the Microsoft Defender portal
226-
href: advanced-hunting-microsoft-defender.md
225+
- name: Hunt over Microsoft Sentinel data
226+
items:
227+
- name: Microsoft Sentinel data in advanced hunting
228+
href: advanced-hunting-microsoft-defender.md
229+
- name: Use functions, saved queries, and custom rules
230+
href: advanced-hunting-defender-use-custom-rules.md
231+
- name: Work with results containing Microsoft Sentinel data
232+
href: advanced-hunting-defender-results.md
227233
- name: Build queries using guided mode
228234
items:
229235
- name: Get started with query builder

defender-xdr/advanced-hunting-defender-results.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Work with advanced hunting results in Microsoft Defender
2+
title: Work with results containing Microsoft Sentinel data
33
description: Work with advanced hunting in the portal unifying Defender XDR and Sentinel data
44
search.appverid: met150
55
ms.service: defender-xdr
@@ -23,7 +23,7 @@ appliesto:
2323
ms.date: 08/07/2024
2424
---
2525

26-
# Work with advanced hunting results in Microsoft Defender
26+
# Work with advanced hunting results containing Microsoft Sentinel data
2727

2828
## Explore results
2929

@@ -58,7 +58,7 @@ You can use the link to incident feature to add advanced hunting query results t
5858

5959
3. In the **Alert details** section in the Link to incident pane, select **Create new incident** to convert the events to alerts and group them to a new incident:
6060

61-
[IMAGE]
61+
6262

6363
You can also select **Link to an existing incident** to add the selected records to an existing incident. Choose the related incident from the dropdown list of existing incidents. You can also enter the first few characters of the incident name or ID to find the incident you want.
6464
:::image type="content" source="/defender/media/advanced-hunting-results-link4.png" alt-text="Screenshot of the options available in saved queries in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-results-link4.png":::

defender-xdr/advanced-hunting-defender-use-custom-rules.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Use custom functions in advanced hunting in Microsoft Defender
2+
title: Use Microsoft Sentinel custom functions in advanced hunting in Microsoft Defender
33
description: Using functions, saved queries, and custom rules in advanced hunting in the portal unifying Defender XDR and Sentinel data
44
search.appverid: met150
55
ms.service: defender-xdr
@@ -23,7 +23,7 @@ appliesto:
2323
ms.date: 08/07/2024
2424
---
2525

26-
# Use advanced hunting functions, saved queries, and custom rules in Microsoft Defender
26+
# Use Microsoft Sentinel functions, saved queries, and custom rules
2727

2828

2929
## Use functions

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Advanced hunting in Microsoft Defender
3-
description: Advanced hunting in the portal unifying Defender XDR and Sentinel data
2+
title: Advanced hunting with Microsoft Sentinel data in Microsoft Defender
3+
description: Learn how to use advanced hunting in the portal unifying Defender XDR and Sentinel data
44
search.appverid: met150
55
ms.service: defender-xdr
66
ms.subservice: adv-hunting
@@ -23,9 +23,9 @@ appliesto:
2323
ms.date: 04/12/2024
2424
---
2525

26-
# Advanced hunting in the Microsoft Defender portal
26+
# Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
2727

28-
Advanced hunting in the unified portal allows you to view and query all data from Microsoft Defender XDR. This includes data from various Microsoft security services and Microsoft Sentinel, which includes data from non-Microsoft products, in a single platform. You can also access and use all your existing Microsoft Sentinel workspace content, including queries and functions.
28+
Advanced hunting in the [unified Microsoft Defender portal](/defender-xdr/microsoft-365-defender-portal) allows you to view and query all data from Microsoft Defender XDR and Microsoft Sentinel, which includes data from non-Microsoft products, in a single platform. You can also access and use all your existing Microsoft Sentinel workspace content, including queries and functions.
2929

3030
Querying from a single portal across different data sets makes hunting more efficient and removes the need for context-switching.
3131

@@ -96,3 +96,4 @@ In the unified portal, in addition to viewing the schema column names and descri
9696

9797
- [Use advanced hunting functions, saved queries, and custom rules](advanced-hunting-defender-use-custom-rules.md)
9898
- [Explore advanced hunting results](advanced-hunting-defender-results.md)
99+
- [Link Microsoft Sentinel incidents](advanced-hunting-link-to-incident.md)

0 commit comments

Comments
 (0)