mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 22:07:22 +00:00
Update custom-detection-rules.md
Adding verbiage about the requirement that the query must return specific fields for each row for it to work. Line 29
This commit is contained in:
parent
00165ed1c4
commit
f0bc757c83
@ -26,7 +26,7 @@ ms.topic: article
|
|||||||
Create custom detection rules from [Advanced hunting](overview-hunting.md) queries to automatically check for threat indicators and generate alerts whenever these indicators are found.
|
Create custom detection rules from [Advanced hunting](overview-hunting.md) queries to automatically check for threat indicators and generate alerts whenever these indicators are found.
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>To create and manage custom detections, [your role](user-roles.md#create-roles-and-assign-the-role-to-an-azure-active-directory-group) needs to have the **manage security settings** permission.
|
>To create and manage custom detections, [your role](user-roles.md#create-roles-and-assign-the-role-to-an-azure-active-directory-group) needs to have the **manage security settings** permission. For the detection rule to work properly and create alerts, the query must return in each row a set of MachineId, ReportId, EventTime which match to an actual event in advanced hunting.
|
||||||
|
|
||||||
1. In the navigation pane, select **Advanced hunting**.
|
1. In the navigation pane, select **Advanced hunting**.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user