mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-17 19:33:37 +00:00
More updates
This commit is contained in:
@ -120,9 +120,9 @@ Selecting an alert using the check box brings up the alerts details pane where y
|
|||||||
|
|
||||||
Clicking on an alert title brings you the alert page.
|
Clicking on an alert title brings you the alert page.
|
||||||
|
|
||||||
### Machines
|
### Devices
|
||||||
|
|
||||||
The **Machines** tab Shows details the device name, IP address, group, users, operating system, remediation level, investigation count, and when it was last investigated.
|
The **Devices** tab Shows details the device name, IP address, group, users, operating system, remediation level, investigation count, and when it was last investigated.
|
||||||
|
|
||||||
Devices that show the same threat can be added to an ongoing investigation and will be displayed in this tab. If 10 or more devices are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view.
|
Devices that show the same threat can be added to an ongoing investigation and will be displayed in this tab. If 10 or more devices are found during this expansion process from the same entity, then that expansion action will require an approval and will be seen in the **Pending actions** view.
|
||||||
|
|
||||||
|
@ -41,12 +41,12 @@ When an alert is triggered, a security playbook goes into effect. Depending on t
|
|||||||
|
|
||||||
## Details of an automated investigation
|
## Details of an automated investigation
|
||||||
|
|
||||||
During and after an automated investigation, you can view details about the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Evidence**, **Entities**, and **Log** tabs.
|
During and after an automated investigation, you can view details about the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Devices**, **Evidence**, **Entities**, and **Log** tabs.
|
||||||
|
|
||||||
|Tab |Description |
|
|Tab |Description |
|
||||||
|--|--|
|
|--|--|
|
||||||
|**Alerts**| Shows the alert that started the investigation.|
|
|**Alerts**| Shows the alert that started the investigation.|
|
||||||
|**Machines** |Shows where the alert was seen.|
|
|**Devices** |Shows where the alert was seen.|
|
||||||
|**Evidence** |Shows the entities that were found to be malicious during the investigation.|
|
|**Evidence** |Shows the entities that were found to be malicious during the investigation.|
|
||||||
|**Entities** |Provides details about each analyzed entity, including a determination for each entity type (*Malicious*, *Suspicious*, or *No threats found*). |
|
|**Entities** |Provides details about each analyzed entity, including a determination for each entity type (*Malicious*, *Suspicious*, or *No threats found*). |
|
||||||
|**Log** |Shows the chronological detailed view of all the investigation actions taken on the alert.|
|
|**Log** |Shows the chronological detailed view of all the investigation actions taken on the alert.|
|
||||||
|
@ -67,7 +67,7 @@ This tile shows you a list of devices with the highest number of active alerts.
|
|||||||
|
|
||||||
Click the name of the device to see details about that device. For more information see, [Investigate devices in the Microsoft Defender Advanced Threat Protection Devices list](investigate-machines.md).
|
Click the name of the device to see details about that device. For more information see, [Investigate devices in the Microsoft Defender Advanced Threat Protection Devices list](investigate-machines.md).
|
||||||
|
|
||||||
You can also click **Devices list** at the top of the tile to go directly to the **Devices list**, sorted by the number of active alerts. For more information see, [Investigate devices in the Microsoft Defender Advanced Threat Protection Devices list](investigate-machines.md).
|
You can also click **Machines list** at the top of the tile to go directly to the **Machines list**, sorted by the number of active alerts. For more information see, [Investigate devices in the Microsoft Defender Advanced Threat Protection Devices list](investigate-machines.md).
|
||||||
|
|
||||||
## Sensor health
|
## Sensor health
|
||||||
The **Sensor health** tile provides information on the individual device’s ability to provide sensor data to the Microsoft Defender ATP service. It reports how many devices require attention and helps you identify problematic devices.
|
The **Sensor health** tile provides information on the individual device’s ability to provide sensor data to the Microsoft Defender ATP service. It reports how many devices require attention and helps you identify problematic devices.
|
||||||
|
Reference in New Issue
Block a user