diff --git a/windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md index 949e57e7a9..7b8c16ee4b 100644 --- a/windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/alerts-queue-windows-defender-advanced-threat-protection.md @@ -35,11 +35,18 @@ To see a list of alerts, click any of the queues under the **Alerts queue** opti > [!NOTE] > By default, the queues are sorted from newest to oldest. +[SME ALERT: PLEASE LET ME KNOW WHICH IMAGE TO USE. FIRST IS TAKEN FROM SEVILLEPORTAL-STG. IT HAS "REFINE YOUR RESULTS BY" FILTERS (TIME, OS, SEVERITY, DETECTION SOURCE). SECOND IMAGE IS TAKEN FROM SECURITYCENTER. ONLY HAS A FEW FILTERS.] + +IMAGE 1 +![Image of alerts queue](images/atp-alertsq1.png) + +IMAGE 2 +![Image of alerts queue](images/atp-alertsq2.png) + + ## Sort, filter, and group the alerts list You can refine the alerts queue list by using the available filters. -![Alerts queue with numbers](images/atp-alerts-queue-user.png) - **Time period**
- 1 day - 3 days @@ -101,6 +108,8 @@ You can take immediate action on an alert and see details about an alert in the ### Use the user details pane Selecting a user brings up the **User details** pane where you can see information such as machine details, related alerts, last IP address, when the machine was first and last seen reporting to the service, and information on the logged on users. +![Alerts queue with numbers](images/atp-alerts-queue-user.png) + ### Bulk edit alerts Select multiple alerts (Ctrl or Shift select) and manage or edit alerts together, which allows resolving multiple similar alerts in one action. diff --git a/windows/threat-protection/windows-defender-atp/images/atp-alertsq1.png b/windows/threat-protection/windows-defender-atp/images/atp-alertsq1.png new file mode 100644 index 0000000000..e137d1bc78 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-alertsq1.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-alertsq2.png b/windows/threat-protection/windows-defender-atp/images/atp-alertsq2.png new file mode 100644 index 0000000000..6780c97e17 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-alertsq2.png differ