Microsoft Sentinel
Cloud and workloads

Surface Custom Details In Alerts

In brief

The article now uses the labels “Microsoft Defender portal” and “Microsoft Azure portal,” and its publication date and authoring metadata were updated.

What Defender admins need to know

Administrators can use the clearer portal labels when following the article; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to surface custom event details in alerts so that I can triage, investigate, and respond to incidents more efficiently.

  1. Enter the Analytics page in the portal through which you access Microsoft Sentinel:

    Microsoft Defender portal

    From the Microsoft Defender navigation menu, expand Microsoft Sentinel, then Configuration. Select Analytics.

    Microsoft Azure portal

    From the Configuration section of the Microsoft Sentinel navigation menu, select Analytics.