Skip to content

Commit 3822f88

Browse files
committed
Scopes - Tomas
1 parent d76814b commit 3822f88

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

articles/sentinel/scoping.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -134,6 +134,9 @@ Alerts inherit scope from the underlying data. Incidents are visible if at least
134134
135135
The `SentinelScope_CF` custom field is available for use in queries and detection rules to reference scope in your analytics.
136136
137+
> [!NOTE]
138+
>When you create custom detections and analytics rules, you must project the `SentinelScope_CF` column in their KQL to make the triggered alerts visible to scoped analysts. If you don't project this column, alerts are unscoped and hidden from scoped users.
139+
137140
:::image type="content" source="./media/scoping/scoped-alerts-view.png" alt-text="Screenshot of alerts filtered by Sentinel scope.":::
138141
139142
## Limitations

0 commit comments

Comments
 (0)