mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-20 21:03:42 +00:00
Merged PR 8269: add dedupe note/tip
add dedupe note/tip
This commit is contained in:
@ -139,6 +139,10 @@ Use the solution explorer to view alerts in Splunk.
|
|||||||
5. Find the query you saved in the list and click **Run**. The results are displayed based on your query.
|
5. Find the query you saved in the list and click **Run**. The results are displayed based on your query.
|
||||||
|
|
||||||
|
|
||||||
|
>[!TIP]
|
||||||
|
> To mininimize alert duplications, you can use the following query:
|
||||||
|
>```source="rest://windows atp alerts" | spath | dedup _raw | table *```
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
- [Enable SIEM integration in Windows Defender ATP](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
||||||
- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)
|
- [Configure ArcSight to pull Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)
|
||||||
|
Reference in New Issue
Block a user