Skip to content

Commit ca86c7b

Browse files
committed
Small edits
1 parent 1ecbad2 commit ca86c7b

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

defender-endpoint/create-custom-data-collection-rules.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,7 @@ Custom data collection is included with Microsoft Defender for Endpoint P2 licen
8282
> [!NOTE]
8383
> If you use the **Not equals** operator with an unexpected value, this might select all events. To avoid using large data volumes, combine this operator with other conditions.
8484
85+
8586
1. Select **Next**.
8687

8788
1. In the **Define rule scope** section, select whether you want to collect data from all applicable client devices or from specific devices that include dynamic tags. For more information, see [Create dynamic rules for devices in asset rule management](/defender-xdr/configure-asset-rules).
@@ -101,7 +102,7 @@ It can take up to an hour for the rule to be deployed to the targeted devices.
101102

102103
If rules aren't working as expected:
103104

104-
- Create a rule to collect network events in an unexpected use case. For example, create a rule that collects all network events where `port not equals 0`.
105+
- Create a broad rule to collect events in an unexpected use case. For example, create a rule that collects all network events where `port not equals 0`.
105106
- Apply individual filters and tags to isolate issues.
106107
- If a device isn't responding after you enable the feature, reboot the device.
107108

0 commit comments

Comments
 (0)