mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 05:47:23 +00:00
Update windows/security/threat-protection/microsoft-defender-atp/custom-detection-rules.md
Co-Authored-By: JohanFreelancer9 <48568725+JohanFreelancer9@users.noreply.github.com>
This commit is contained in:
parent
c9871554bb
commit
f498ca39b7
@ -41,7 +41,7 @@ In Microsoft Defender Security Center, go to **Advanced hunting** and select an
|
||||
| where EventTime > ago(7d)
|
||||
| where ActionType == "AntivirusDetection"
|
||||
| summarize (EventTime, ReportId)=arg_max(EventTime, ReportId), count() by MachineId
|
||||
This will fetch latest EventTime and ReportId of the latest event among multiple events returned by the query and adds the count by MachineId.
|
||||
This will fetch the EventTime and ReportId of the latest event from multiple events returned by the query and adds the count by MachineId.
|
||||
|
||||
### 2. Create new rule and provide alert details.
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user