Microsoft Sentinel
Incidents and response

Customize Alert Details

In brief

The article now directs readers to its alert details properties table for customization guidance and for identifying preview-labeled properties. It also updates the publication metadata and related-content introduction.

What Defender admins need to know

Administrators can use the properties table to find customization and preview information more directly. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to customize alert details in my analytics rules so that I can ensure alerts are more relevant and actionable based on specific query results.

  • Create custom, variable names and descriptions for your alerts. You can select fields in your alert's query output whose contents can be included in the name or description of each instance of the alert. If the selected field has no value in a given instance, the alert details for that instance will revert to the defaults specified on the General page of the analytics rule wizard.

  • Customize the severity, tactics, and other properties of a given instance of an alert (see the full list ofalert details properties below)table in this article) with the values of any relevant fields from the query output. If the selected fields are empty or have values that don't match the field data type, the respective alert properties will revert to their defaults (for tactics and severity, the values specified on the General page of the analytics rule wizard).

Use the following procedure to customize alert details. These steps are part of the Microsoft Sentinel analytics rule creation wizard, but they're addressed here independently to address the scenario of adding or changing alert details in an existing analytics rule.

Next steps

In this document, you learned how to customize alert details in Microsoft Sentinel analytics rules. To learnFor more information about alert enrichment, analytics rules, and entities in Microsoft Sentinel, see these related articles: