Skip to content

Commit fb53265

Browse files
committed
Edits for bookmark
1 parent c4f9509 commit fb53265

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -87,13 +87,12 @@ In the unified portal, in addition to viewing the schema column names and descri
8787
- Near real-time detection frequency is not available for detections that include Microsoft Sentinel data.
8888
- Custom functions that were created and saved in Microsoft Sentinel are not supported.
8989
- Defining entities from Sentinel data is not yet supported in custom detections.
90-
- Bookmarks aren't supported in the advanced hunting experience. They're supported in the **Microsoft Sentinel > Threat management > Hunting** feature.
90+
- Bookmarks aren't supported in the advanced hunting experience. They're supported in the **Microsoft Sentinel > Threat management > Hunting** feature. You can also use the [link to incident](advanced-hunting-defender-results.md#link-results-to-new-or-existing-incidents) feature to link events to incidents.
9191
- If you're streaming Defender XDR tables to Log Analytics, there might be a difference between the`Timestamp` and `TimeGenerated` columns. In case the data arrives to Log Analytics after 48 hours, it's being overridden upon ingestion to `now()`. Therefore, to get the actual time the event happened, we recommend relying on the `Timestamp` column.
9292
- When prompting [Copilot for Security](advanced-hunting-security-copilot.md) for advanced hunting queries, you might find that not all Microsoft Sentinel tables are currently supported. However, support for these tables can be expected in the future.
9393

9494

9595
## See also
9696

9797
- [Use advanced hunting functions, saved queries, and custom rules](advanced-hunting-defender-use-custom-rules.md)
98-
- [Explore advanced hunting results](advanced-hunting-defender-results.md)
99-
- [Link Microsoft Sentinel incidents](advanced-hunting-link-to-incident.md)
98+
- [Explore advanced hunting results with Microsoft Sentinel data](advanced-hunting-defender-results.md)

0 commit comments

Comments
 (0)