Skip to content

Commit fecb71f

Browse files
committed
added the connectors to intro
1 parent dddd816 commit fecb71f

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

articles/sentinel/security-alert-schema-differences.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Alert schema differences between standalone and XDR connectors
2+
title: Microsoft Sentinel alert schema differences between standalone and XDR connectors
33
description: Learn how alert schema, field mappings, and ingestion behavior differ between standalone connectors and the XDR connector in Microsoft Sentinel.
44
author: guywi-ms
55
ms.author: guywild
@@ -13,7 +13,7 @@ ms.date: 01/27/2026
1313

1414
This article explains the differences between alerts ingested through standalone connectors and alerts ingested through the Extended Detection and Response (XDR) connector in Microsoft Sentinel.
1515

16-
Standalone connectors ingest alerts directly from the original security products, whereas the XDR connector ingests alerts through the Microsoft Defender XDR pipeline.
16+
Standalone connectors ingest alerts directly from the original security products, whereas the XDR connector ingests alerts through the Microsoft Defender XDR pipeline. This includes connectors such as Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Information Rights Management (IRM), Data Loss Prevention (DLP), Microsoft Defender for Cloud (MDC), and Microsoft Defender for Cloud Apps (MDA).
1717

1818
These differences can affect field mappings, derived field behavior, schema structure, and alert ingestion, which might impact your existing queries, analytic rules, and workbooks. Review these differences before migrating to the XDR connector.
1919

0 commit comments

Comments
 (0)