Skip to content

Commit e2794e5

Browse files
authored
Merge pull request #22755 from MicrosoftDocs/chrfox-filters-defender
Update dlp-investigate-alerts-defender.md
2 parents 5122db0 + 59c0ac8 commit e2794e5

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

microsoft-365/security/defender/dlp-investigate-alerts-defender.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.topic: how-to
1818
search.appverid:
1919
- MOE150
2020
- met150
21-
ms.date: 10/27/2023
21+
ms.date: 11/14/2023
2222
---
2323

2424
# Investigate data loss prevention alerts with Microsoft 365 Defender
@@ -77,7 +77,10 @@ It's best practice to only grant minimal permissions to alerts in the Microsoft
7777

7878
1. Go to the Microsoft 365 Defender portal, and select **Incidents** in the left hand navigation menu to open the incidents page.
7979

80-
1. Select **Filters** on the top right, and choose **Service Source : Data Loss Prevention** to view all incidents with DLP alerts.
80+
2. Select **Filters** on the top right, and choose **Service Source : Data Loss Prevention** to view all incidents with DLP alerts. Here's a few examples of the subfilters that are available in preview:
81+
1. by user and device names
82+
1. (in preview) In the **Entities** filter, you can search on file names, user, device names, and file paths.
83+
1. (in preview) In the **Incidents** queue > **Alert policies** > Alert policy title. You can search on the DLP policy name.
8184

8285
1. Search for the DLP policy name of the alerts and incidents you're interested in.
8386

0 commit comments

Comments
 (0)