Skip to content

Commit 0a44c2d

Browse files
committed
Added hidden comment
1 parent c5aba92 commit 0a44c2d

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/search/search-query-language/search-operators/threatlookup.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,8 @@ You cannot use the cat search operator with the `SumoLogic_ThreatIntel` source.
132132
:::
133133
-->
134134

135+
<!-- Remove the following "Upcoming change" section at GA. -->
136+
135137
## Upcoming change
136138

137139
The behavior of the `threatlookup` operator is changing in an upcoming release. Previously, rows without matches in threat intelligence sources were excluded from search results. With the new behavior, `threatlookup` will return one result row for each input indicator, even if there is no threat intel match. In such cases, the normalized threatlookup fields (for example, `_threatlookup.source`, `_threatlookup.confidence`, etc.) will be `null`.

0 commit comments

Comments
 (0)