add intro, update image

This commit is contained in:
Joey Caparas
2017-05-31 12:04:56 -07:00
parent a532a95978
commit b2d4020517
2 changed files with 8 additions and 3 deletions

View File

@ -25,6 +25,13 @@ Understand what data fields are exposed as part of the alerts API and how they m
## Alert API fields and portal mapping ## Alert API fields and portal mapping
The following table lists the available fields exposed in the alerts API payload. It shows examples for the populated values and a reference on how data is reflected on the portal.
The ArcSight field column contains the default mapping between the Windows Defender ATP fields and the built-in fields in ArcSight.
The mapping file is available for download when you enable the SIEM integration feature in the portal and can be modified to match your organization needs.
Field numbers match the numbers in the images below. Field numbers match the numbers in the images below.
<table style="table-layout:fixed;width:100%" > <table style="table-layout:fixed;width:100%" >
@ -263,9 +270,7 @@ Field numbers match the numbers in the images below.
</table> </table>
![Image of alert with numbers](images/atp-siem-mapping1.png) ![Image of alert with numbers](images/atp-alert-page.png)
![Image of alert with numbers](images/1.png)
![Image of alert details pane with numbers](images/atp-siem-mapping13.png) ![Image of alert details pane with numbers](images/atp-siem-mapping13.png)

Binary file not shown.

Before

Width:  |  Height:  |  Size: 17 KiB

After

Width:  |  Height:  |  Size: 58 KiB