Microsoft Sentinel
Cloud and workloads

Work With Anomaly Rules

In brief

The anomaly comparison step now links more clearly to the quality assessment guidance, and the anomaly detection resources heading was revised. Page metadata was also updated.

What Defender admins need to know

No administrator action is required; the revised wording may make the comparison procedure easier to follow.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to customize and tune anomaly detection rules so that I can improve the accuracy and relevance of alerts in my environment.

  1. Enable the customized rule to generate results. Some of your changes may require the rule to run again, so you must wait for it to finish and come back to check the results on the logs page. The customized anomaly rule runs in Flighting (testing) mode by default. The original rule continues to run in Production mode by default.

  2. To compare the results, go back to the Anomalies table in Logs to assess the new rule as described earlier in Assess the quality of anomalies, onlybut use the following query instead to look for anomalies generated by the original rule as well as the duplicate rule.

    Anomalies
    

Next steps

ForLearn more information about anomaly detection in Microsoft Sentinel, see the following resources:Sentinel: