
Microsoft Security Operations Analyst Exam Ref SC-200 Certification Guide
By :

During this chapter, we will be using the terms feeds and alerts very frequently. We want to ensure that you have a full understanding of the differences and the use cases. What is a feed? What is an alert? Let's get right into this!
A feed is a constant stream of activity that has been configured for ingestion or analysis. This activity is used for statistical purposes, and sometimes this is referred to as an audit trail or log/logging:
An alert is a notification generated in response to an event or a sequence of events that is characteristic of suspicious behavior. The alert is intended to bring the event(s) to the attention of an operator or a Security Operations Center (SOC) analyst: