Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions defender-xdr/entity-page-device.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,6 +145,17 @@ You can elect not to show events from Microsoft Sentinel in the main timeline, a

For more information about these activity events, see [Entity pages in Microsoft Sentinel](/azure/sentinel/entity-pages?tabs=defender-portal#entity-pages).

#### Strong identifier requirements for unified timeline (Sentinel to XDR mapping)

To ensure that custom activity data (for example, Sophos alerts) is correctly mapped and visible in **Microsoft Defender XDR** (`security.microsoft.com`) under the **Device Timeline**, the ingested data must include a strong identifier combination for the host.

#### Required strong identifiers

At a minimum, include one of the following strong identifier combinations:

- `HostName` + `NTDomain`
- `HostName` + `DnsDomain`

> [!NOTE]
>
> For firewall events to be displayed, you'll need to enable the audit policy. For instructions, see [Audit Filtering Platform connection](/windows/security/threat-protection/auditing/audit-filtering-platform-connection).
Expand Down