fix notes and warnings

This commit is contained in:
Joey Caparas 2017-03-22 15:25:07 -07:00
parent ae0db8ec8a
commit c5e0342956
6 changed files with 22 additions and 16 deletions

View File

@ -70,6 +70,7 @@ The following steps assume that you have completed all the required steps in [Be
> [!NOTE] > [!NOTE]
> You must put the configuration files in this location, where *folder_location* represents the location where you installed the tool. > You must put the configuration files in this location, where *folder_location* represents the location where you installed the tool.
4. After the installation of the core connector completes, the Connector Setup window opens. In the Connector Setup window, select **Add a Connector**. 4. After the installation of the core connector completes, the Connector Setup window opens. In the Connector Setup window, select **Add a Connector**.
5. Select Type: **ArcSight FlexConnector REST** and click **Next**. 5. Select Type: **ArcSight FlexConnector REST** and click **Next**.

View File

@ -42,12 +42,14 @@ You'll need to configure Splunk so that it can pull Windows Defender ATP alerts.
2. Click **Search & Reporting**, then **Settings** > **Data inputs**. 2. Click **Search & Reporting**, then **Settings** > **Data inputs**.
3. Click **REST** under **Local inputs**. 3. Click **REST** under **Local inputs**.
> [!NOTE] > [!NOTE]
> This input will only appear after you install the [REST API Modular Input app](https://splunkbase.splunk.com/app/1546/). > This input will only appear after you install the [REST API Modular Input app](https://splunkbase.splunk.com/app/1546/).
4. Click **New**. 4. Click **New**.
5. Type the following values in the required fields, then click **Save**: 5. Type the following values in the required fields, then click **Save**:
> [!NOTE] > [!NOTE]
> All other values in the form are optional and can be left blank. > All other values in the form are optional and can be left blank.

View File

@ -34,6 +34,7 @@ Enable security information and event management (SIEM) integration so you can p
> For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md#learn-how-to-get-a-new-client-secret). > For more information about getting a new secret see, [Learn how to get a new secret](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md#learn-how-to-get-a-new-client-secret).
3. Choose the SIEM type you use in your organization. 3. Choose the SIEM type you use in your organization.
> [!NOTE] > [!NOTE]
> If you select HP ArcSight, you'll need to save these two configuration files: > If you select HP ArcSight, you'll need to save these two configuration files:
> - WDATP-connector.jsonparser.properties > - WDATP-connector.jsonparser.properties

View File

@ -23,10 +23,12 @@ localizationpriority: high
During the onboarding process, a wizard takes you through the general settings of Windows Defender ATP. After onboarding, you might want to update some settings which you'll be able to do through the **Preferences setup** menu. During the onboarding process, a wizard takes you through the general settings of Windows Defender ATP. After onboarding, you might want to update some settings which you'll be able to do through the **Preferences setup** menu.
1. In the navigation pane, select **Preferences setup** > **General**. 1. In the navigation pane, select **Preferences setup** > **General**.
2. Modify settings such as data retention policy or the industry that best describes your organization. 2. Modify settings such as data retention policy or the industry that best describes your organization.
> [!NOTE] > [!NOTE]
> Other settings are not editable. > Other settings are not editable.
3. Click **Save preferences**. 3. Click **Save preferences**.

Binary file not shown.

Before

Width:  |  Height:  |  Size: 104 KiB

After

Width:  |  Height:  |  Size: 75 KiB