Skip to content

Commit e90fef6

Browse files
committed
wi-454109-uuf-custom-detail-key-does-not-contain
1 parent 98a8d46 commit e90fef6

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

articles/sentinel/create-manage-use-automation-rules.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: This article explains how to create and use automation rules in Mic
44
ms.topic: how-to
55
author: batamig
66
ms.author: bagol
7-
ms.date: 10/16/2024
7+
ms.date: 02/24/2026
88
appliesto:
99
- Microsoft Sentinel in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -244,6 +244,8 @@ Select **+ Add item condition**.
244244

245245
In this example, if the incident has the custom detail *DestinationEmail*, and if the value of that detail is `[email protected]`, the actions defined in the automation rule will run.
246246

247+
**Known limitation**: When using custom detail values, the **Does not contain** operator might fail to evaluate correctly when multiple (two or more) distinct values are present.
248+
247249
### Add actions
248250

249251
Choose the actions you want this automation rule to take. Available actions include **Assign owner**, **Change status**, **Change severity**, **Add tags**, and **Run playbook**. You can add as many actions as you like.

0 commit comments

Comments
 (0)