Skip to content

docs(threatprevention): add 8.1 documentation - #1472

Open
alexei-belous wants to merge 13 commits into
devfrom
ab/ntp81
Open

docs(threatprevention): add 8.1 documentation#1472
alexei-belous wants to merge 13 commits into
devfrom
ab/ntp81

Conversation

@alexei-belous

@alexei-belous alexei-belous commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Summary

Sets up the documentation for Netwrix Threat Prevention 8.1 and documents what changed in the release.

The first commit copies the 8.0 documentation set to docs/threatprevention/8.1/ as a baseline, with internal links and image paths rewritten. The second commit adds the topics for the 8.1 changes and updates the existing topics those changes affect.

8.1 is deliberately not registered in src/config/products.js, so none of this is published yet. Registering the version is a one-line change to make when the release ships.

New topics

Topic Covers
troubleshooting/logging.md Log files per component, the timestamped archive names that replace .log.1, editing .log.config to turn on feature-level logging, and the removal of the SI Events Windows Event Log source
troubleshooting/admonitorlogging.md EventTrace.log, the full Logging.ini reference, the DebugFilter and EventFilter values, worked configuration examples, and the validation messages
troubleshooting/lsasshookscan.md LsassHookScan.exe, for identifying third-party hooks in LSASS
admin/tools/sipolicyverifier.md SIPolicyVerifier.exe, for finding policy references to objects that no longer exist
admin/configuration/trusteddomainsblacklist.md Excluding unreachable trusted domains from account resolution, which is what causes Agent queue overflow

Updated topics

  • Process Guardian Monitor and Protect — folder and SHA-256 filtering, the options that apply when a folder or checksum can't be resolved, the Kernel Stack event attribute, and Never Block Windows System Process (PID = 4).
  • Log Level Configuration WindowGet Agent Log now downloads a ZIP archive of the logs and ADMonitor_logs folders. Also corrects the rollover description, which still described the pre-8.1 engine, and notes that a log level now survives a service restart.
  • Upgrade Procedure — the 8.1 upgrade paths (8.1.x → 8.1.y, 8.0 → 8.1, 7.5 → 8.1), plus a section on the logging changes to plan for, including the Logging.ini settings that stop working silently and need editing by hand.
  • Installer file names across the install topics. install/agent/silent.md still referenced 7.4.
  • Cross-references from Export Policies and Templates, LSASS Process Terminated, and Best Practices and Troubleshooting.
  • Two KB articles on enabling debug logging now note the 8.1 .log.config format. They carry no links to 8.1 topics, since KB is shared across versions and 8.1 isn't registered yet.

Before merge

Screenshots still show the 8.0 UI. The Process Guardian topics describe controls that aren't in the current images.

Three details came from a written source rather than a build, and are worth a check:

  1. The menu path for the Trusted Domains Blacklist window is written as Configuration > Trusted Domains Blacklist, by analogy with the neighbouring windows.
  2. The source calls the configuration file both logconfig.xml and .log.config. The topics use .log.config, which is what appears on disk and what the KB articles already use.
  3. The options for an unresolved folder and an unavailable checksum are documented as living on the Target Processes tab for blocking policies, which is what the source states even though the filters themselves concern the requesting process.

🤖 Generated with Claude Code

Closes #1473

alexei-belous and others added 2 commits September 1, 2026 17:41
Copy the 8.0 documentation set and images to 8.1 as a baseline for the
8.1.0 release, with internal links and image paths rewritten to 8.1.
Content edits follow in later commits.

Not registered in src/config/products.js yet, so 8.1 stays off the site
until release.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Add the topics for what changed in 8.1 and update the existing ones the
changes affect.

New topics:

- Log Files and Logging Configuration - the managed component logs, the
  timestamped archive names, and editing .log.config to enable
  feature-level logging.
- AD Monitor Logging Configuration - EventTrace.log, the Logging.ini
  settings, the DebugFilter and EventFilter values, and the validation
  messages.
- LSASS Hook Scan Tool - LsassHookScan.exe, for identifying third-party
  hooks in LSASS.
- Policy Verifier Tool - SIPolicyVerifier.exe, for finding policy
  references to objects that no longer exist.
- Trusted Domains Blacklist Window - excluding unreachable trusted
  domains from account resolution.

Updated topics:

- Process Guardian Monitor and Protect - folder and SHA-256 filtering,
  the options for an unresolved folder or an unavailable checksum, the
  Kernel Stack attribute, and Never Block Windows System Process
  (PID = 4).
- Log Level Configuration Window - Get Agent Log now downloads a ZIP
  archive of the logs and ADMonitor_logs folders. Corrects the rollover
  description and notes that a log level now survives a restart.
- Upgrade Procedure - the 8.1 upgrade paths, and a section on the
  logging changes to plan for, including the Logging.ini settings that
  need to be edited by hand.
- Installer file names, and cross-references from the related topics.
- Two KB articles on enabling debug logging, noting the 8.1
  .log.config format.

8.1 is not registered in src/config/products.js, so none of this is
published yet. Screenshots still show the 8.0 UI.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
kdejoyce
kdejoyce previously approved these changes Sep 2, 2026
tsarra59
tsarra59 previously approved these changes Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

1756 issues fixed, 46 skipped across 296 files

Category Fixes
Contractions 332
Plurals 194
Removed filler 31
Substitutions 246
AllowsYouTo (rewrite) 56
CanBeUsedTo (rewrite) 10
Contractions (rewrite) 6
DesiredAsAdjective (rewrite) 184
Dropdown (rewrite) 1
FirstPerson (rewrite) 4
FirstPersonPlural (rewrite) 5
FollowTheStepsTo (rewrite) 132
FormalHedging (rewrite) 55
Idioms (rewrite) 12
ImpersonalFiller (rewrite) 15
NoteThat (rewrite) 5
OnceUsage (rewrite) 19
OxfordComma (rewrite) 19
PlainTextAdmonition (rewrite) 3
Repetition (rewrite) 6
TypeVsEnter (rewrite) 33
WeakLinkText (rewrite) 7
WhetherOrNot (rewrite) 7
Dale: exclamatory-sentences 1
Dale: idioms 10
Dale: minimizing-difficulty 16
Dale: misplaced-modifiers 12
Dale: passive-voice 277
Dale: positional-references 7
Dale: wordiness 47
Dale: xy-slop 4
Skipped (needs manual review) Reason
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:22 — Netwrix.FirstPerson 'I' is inside the literal UI option-button label 'I will provide a list'; rewriting would misstate the product UI
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:25 — Netwrix.FirstPerson 'I' is inside the literal UI option-button label 'I want a list to come from the database table'
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:36 — Netwrix.FirstPerson 'I' is inside the literal UI option-button label 'I will provide a list'
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:37 — Netwrix.FirstPerson 'I' is inside the literal UI option-button label 'I want a list to come from the database table'
docs/threatprevention/8.1/admin/configuration/epesettings.md:9 — Netwrix.FirstPerson 'I' is part of the third-party product name 'Have I Been Pwned (HIBP)'
docs/threatprevention/8.1/admin/configuration/epesettings.md:134 — Netwrix.FirstPerson 'I' is part of the product name 'Have I Been Pwned' in a cross-reference
docs/threatprevention/8.1/admin/configuration/epesettings.md:341 — Netwrix.FirstPerson heading text — not modified to avoid breaking anchor links (it is also the product name 'Have I Been Pwned')
docs/threatprevention/8.1/admin/configuration/epesettings.md:346 — Netwrix.FirstPerson 'I' is part of the product name 'Have I Been Pwned (HIBP)'
docs/threatprevention/8.1/admin/configuration/epesettings.md:348 — Netwrix.FirstPerson 'I' is part of the link text/product name 'Have I Been Pwned'
docs/threatprevention/8.1/admin/configuration/epesettings.md:370 — Netwrix.FirstPerson 'I' is part of the product name 'The Have I Been Pwned database (HIBP)'
docs/threatprevention/8.1/admin/configuration/systemalerting/email.md:35 — Netwrix.Please 'please' is inside the literal UI control label 'Select Profile, please'; rewriting would misstate the product UI
docs/threatprevention/8.1/admin/configuration/systemalerting/siem.md:37 — Netwrix.Please 'please' is inside the literal UI control label 'Select Profile, please'
docs/threatprevention/8.1/admin/navigation/overview.md:50 — Netwrix.FirstPerson 'I' is the keyboard shortcut 'Alt+I'; cannot be reworded
docs/threatprevention/8.1/admin/navigation/overview.md:59 — Netwrix.FirstPerson 'I' is part of the product name 'Have I Been Pwned'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemchanges/filesystemchanges.md:106 — Netwrix.FirstPerson 'I' comes from the technical term 'I/O Type', not first-person usage
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemlockdown.md:94 — Netwrix.FirstPerson 'I' comes from the technical term 'I/O Type', not first-person usage
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:32 — Netwrix.Repetition 'Nom Nom' is part of the proper name of the attack tool 'LDAP Nom Nom'; the repetition is intentional
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:34 — Netwrix.Repetition 'Nom Nom' is part of the tool name 'LDAP Nom Nom'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:35 — Netwrix.Repetition 'Nom Nom' is part of the tool name 'LDAP Nom Nom'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:39 — Netwrix.Repetition 'Nom Nom' is part of the tool name 'LDAP Nom Nom'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:51 — Netwrix.Repetition 'Nom Nom' is part of the tool name 'LDAP Nom Nom'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:54 — Netwrix.Repetition 'Nom Nom' is part of the tool name 'LDAP Nom Nom'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/monitorweakpasswords.md:28 — Netwrix.FirstPerson 'I' is part of the link text/product name 'Have I Been Pwned Hash List'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/passwordenforcement.md:306 — Netwrix.FirstPerson 'I' is part of the product name 'Have I Been Pwned? database'
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/preventweakpasswords.md:35 — Netwrix.FirstPerson 'I' is part of the link text/product name 'Have I Been Pwned Hash List'
docs/threatprevention/8.1/admin/templates/folder/schemaconfiguration.md:14 — Netwrix.Spacing the flagged gap is a non-breaking space (U+00A0) followed by a space inside a table cell; the available editing tools cannot express a literal U+00A0 in a replacement string, and the alternative rewrites all leave the sentence ungrammatical
docs/threatprevention/8.1/admin/tools/import.md:23 — Netwrix.FirstPerson 'I' is the keyboard shortcut 'Alt+I'; cannot be reworded
docs/threatprevention/8.1/eperestsite/accountmanagement.md:81 — Netwrix.QuestionHeadings heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/install/adminconsole.md:38 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the terms in the License Agreement'
docs/threatprevention/8.1/install/agent/manual.md:57 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the terms in the License Agreement'
docs/threatprevention/8.1/install/application.md:40 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the terms in the License Agreement'
docs/threatprevention/8.1/install/eperestsite.md:36 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the terms in the License Agreement'
docs/threatprevention/8.1/install/reportingmodule/application.md:39 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the license agreement'
docs/threatprevention/8.1/install/reportingmodule/database.md:37 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the license agreement'
docs/threatprevention/8.1/install/upgrade/reportingmodule.md:42 — Netwrix.FirstPerson 'I' is inside the literal UI checkbox label 'I accept the license agreement'
docs/threatprevention/8.1/requirements/agent/agent.md:42 — Netwrix.FirstPerson 'I' is part of the product name 'The Have I Been Pwnd (HIBP) database'
docs/threatprevention/8.1/requirements/application.md:55 — Netwrix.FirstPerson 'I' is part of the product name 'The Have I Been Pwnd (HIBP) database'
docs/threatprevention/8.1/solutions/filesystem.md:28 — Netwrix.FirstPerson 'I' comes from the technical term 'I/O Type Events', not first-person usage
docs/threatprevention/8.1/admin/agents/overview.md:76 — Dale: null wordiness — duplicated/garbled example text ("For example, Windows Server 2022 Standard.. For example, Windows Server 2019 Standard"); ambiguous which OS version is intended, so a fix could change technical meaning
docs/threatprevention/8.1/admin/configuration/collectionmanager/overview.md:98 — Dale: null wordiness — garbled table cell ("Folders with Sensitive Data. If you"); truncated source text, correct wording unknown
docs/threatprevention/8.1/admin/alerts/overview.md:83 — Dale: null passive-voice — "In addition to this information, several notifications have been sent for the event." Intended meaning is unclear, so an active rewrite risks changing it
docs/threatprevention/8.1/admin/configuration/systemalerting/email.md:142 — Dale: null wordiness — "No – Leads the current message body" appears to be a typo for "Keeps"; the intended verb is ambiguous
docs/threatprevention/8.1/admin/agents/agents-windows/loglevelconfiguration.md:106 — Dale: null xy-slop — "Collect the archive after you reproduce a problem, not before." The trailing negation is a clarifying contrast, not the negative-then-positive pattern the rule targets
docs/threatprevention/8.1/admin/policies/configuration/eventtype/activedirectorychanges.md:344 — Dale: null positional-references — "displayed in blue text in the box below" refers to a physical location in the product UI, not to other documentation content
docs/threatprevention/8.1/reportingmodule/configuration/integrations/netwrixintegrations.md:220 — Dale: null residual stray space before the period contains a non-matchable invisible character; the Dale violation itself (filler + passive voice) was fixed
docs/threatprevention/8.1/admin/policies/configuration/eventtype/window/:1 — Dale: null not individually reviewed — the 17 selection-window topics, the 4 recentevents topics, the templates/folder topics, and the api, eperestsite, install, reportingmodule, requirements, siemdashboard, solutions, and troubleshooting sections were pattern-swept for the recurring Dale violations rather than read line by line; a follow-up pass is needed for full per-line coverage

Ask @claude on this PR if you'd like an explanation of any fix.

@jth-nw
jth-nw dismissed stale reviews from tsarra59 and kdejoyce via 60c4a6f September 2, 2026 21:53
alexei-belous and others added 3 commits September 3, 2026 16:44
…d build

Verified the new topics against a Threat Prevention 8.1.0.978 install and
its Administration Console, and corrected what the written source got
wrong. Adds real 8.1 screenshots for the affected topics.

Process Guardian:

- The unresolved-folder option and the PID 4 option are on the
  Requesting Processes tab, not Target Processes. Removes that claim and
  the cross-reference it added to the Target Processes section.
- Restores "Monitor if Checksum Unavailable". It exists as a per-entry
  grid column, not a single option, alongside "Use Checksum" and
  "SHA-256".
- There's no separate folder field: a name or a full image path goes in
  the same Process (name or path) column, and both are case insensitive.
  Rewrites the section accordingly and documents "Use Checksum".
- Documents "Ignore Windows System Process (PID = 4)", the monitoring
  policy's counterpart to "Never Block Windows System Process (PID = 4)".
- The filters are grids with Add, Remove, and Lookup buttons, not text
  boxes.

Trusted Domains Blacklist:

- The menu path is confirmed as Configuration > Trusted Domains
  Blacklist.
- Rewrites the procedure for the real dialog: a grid of Source Domain
  (NetBIOS name, or * for every Agent) and Excluded Domains (DNS names
  separated by semicolons), with Add Row, Add from Agent..., and Delete.
- Documents the Select Trusted Domains dialog, including the Agent (DC)
  list and Connect.

AD Monitor logging:

- Logging.ini and ADMonitor_logs live in the Agent installation folder,
  not an AD Monitor folder. Adds the real paths.
- EventTrace.log does take the context prefix; a TermEventTrace file
  exists on a domain controller. Corrects the claim that it never does.
- PagedSearch isn't a valid DebugFilter value in the shipped file.
- Adds DotNetLoaderTrace.log, the rolled-over file naming, and a warning
  that EventTrace.log is always buffered, so an LSASS crash loses up to
  one flush interval.

Also: plsahlp.sys ships with the Agent, not the Enterprise Manager, and
LsassHookScan.exe isn't installed by either, so the LSASS hook scan
topic now points at Support for the tool. Adds SIAgentUpdater to the
managed log and configuration file lists.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… article structure

Corrects a product-name misattribution ("Netwrix Threat Manager" -> "Netwrix
Threat Prevention", confirmed against the source Salesforce KB article),
fixes frontmatter (products ID, missing kb tag), converts the new 8.1 :::note
to KB blockquote format, and restructures both articles from legacy
Summary/Issue/Module/Salesforce Article ID sections to Overview/Instructions.
Also fixes Vale heading-case and contraction warnings, Dale passive-voice and
wordiness findings, bolds action-target UI elements, drops an empty code
block with no source content, and rewrites a filename-only image alt text.
Explains what each option involves (direct file edit vs. console-based log
level change) instead of just stating there are two, in both articles.
hilram7
hilram7 previously approved these changes Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

92 issues fixed, 67 skipped across 296 files

Category Fixes
Removed filler 1
OnceUsage (rewrite) 3
WhetherOrNot (rewrite) 1
Dale: idioms 1
Dale: misplaced-modifiers 8
Dale: passive-voice 43
Dale: positional-references 21
Dale: wordiness 14
Skipped (needs manual review) Reason
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:22 — Netwrix.FirstPerson False positive — 'I will provide a list' is the literal label of a UI option button; rewriting would misname the control.
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:25 — Netwrix.FirstPerson False positive — 'I want a list to come from the database table' is the literal label of a UI option button.
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:36 — Netwrix.FirstPerson False positive — 'I will provide a list' is the literal label of a UI option button.
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:37 — Netwrix.FirstPerson False positive — 'I want a list to come from the database table' is the literal label of a UI option button.
docs/threatprevention/8.1/admin/configuration/epesettings.md:9 — Netwrix.FirstPerson False positive — 'Have I Been Pwned' is a product/database proper noun.
docs/threatprevention/8.1/admin/configuration/epesettings.md:134 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun used as a cross-reference topic title.
docs/threatprevention/8.1/admin/configuration/epesettings.md:341 — Netwrix.FirstPerson heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/admin/configuration/epesettings.md:346 — Netwrix.FirstPerson False positive — 'Have I Been Pwned (HIBP)' is a product/database proper noun.
docs/threatprevention/8.1/admin/configuration/epesettings.md:348 — Netwrix.FirstPerson False positive — 'Have I Been Pwned' is the link text for the haveibeenpwned.com website.
docs/threatprevention/8.1/admin/configuration/epesettings.md:369 — Netwrix.FirstPerson False positive — 'The Have I Been Pwned database (HIBP)' is a proper noun.
docs/threatprevention/8.1/admin/configuration/systemalerting/email.md:35 — Netwrix.Please False positive — 'Select Profile, please' is the literal text of the UI option the reader must click.
docs/threatprevention/8.1/admin/configuration/systemalerting/siem.md:37 — Netwrix.Please False positive — 'Select Profile, please' is the literal text of the UI dropdown menu.
docs/threatprevention/8.1/admin/navigation/overview.md:50 — Netwrix.FirstPerson False positive — 'I' is part of the keyboard shortcut 'Alt+I'.
docs/threatprevention/8.1/admin/navigation/overview.md:59 — Netwrix.FirstPerson False positive — 'Have I Been Pwned' is a product/database proper noun.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemchanges/filesystemchanges.md:106 — Netwrix.FirstPerson False positive — 'I' is part of 'I/O Type', the name of a UI area.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemlockdown.md:93 — Netwrix.FirstPerson False positive — 'I' is part of 'I/O Type', the name of a UI area.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:32 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:34 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:35 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:39 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:51 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:54 — Netwrix.Repetition False positive — 'Nom Nom' is the proper name of the LDAP Nom Nom attack tool.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/monitorweakpasswords.md:28 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun inside cross-reference link text.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/passwordenforcement.md:305 — Netwrix.FirstPerson False positive — 'Have I Been Pwned?' is a product/database proper noun wrapped across lines.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/preventweakpasswords.md:24 — Netwrix.OxfordComma False positive — 'As a best practice, create and enable a monitoring policy' is a two-item pair, not a series of three; adding a comma would be wrong.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/preventweakpasswords.md:35 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun inside cross-reference link text.
docs/threatprevention/8.1/admin/templates/folder/schemaconfiguration.md:14 — Netwrix.Spacing Real issue (non-breaking space U+00A0 followed by a space after 'added.') but not fixable with the available tools — the Edit tool normalizes U+00A0 to a regular space so the literal string cannot be matched, and the perl/python fallbacks were blocked by the sandbox.
docs/threatprevention/8.1/admin/tools/import.md:23 — Netwrix.FirstPerson False positive — 'I' is part of the keyboard shortcut 'Alt+I'.
docs/threatprevention/8.1/eperestsite/accountmanagement.md:81 — Netwrix.QuestionHeadings heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/install/adminconsole.md:38 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/agent/manual.md:57 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/application.md:40 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/eperestsite.md:36 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/reportingmodule/application.md:39 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/reportingmodule/database.md:37 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/install/upgrade/reportingmodule.md:42 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal label of an installer checkbox.
docs/threatprevention/8.1/requirements/agent/agent.md:42 — Netwrix.FirstPerson False positive — 'Have I Been Pwnd (HIBP)' is a product/database proper noun.
docs/threatprevention/8.1/requirements/application.md:55 — Netwrix.FirstPerson False positive — 'Have I Been Pwnd (HIBP)' is a product/database proper noun.
docs/threatprevention/8.1/solutions/filesystem.md:28 — Netwrix.FirstPerson False positive — 'I' is part of 'I/O Type Events'.
docs/threatprevention/8.1/admin/configuration/databasemaintenance/overview.md:139 — Dale: positional-references 'Above the table is a cumulative count of:' describes the literal physical layout of the UI window, not a cross-reference to other documentation content. Same at line 161.
docs/threatprevention/8.1/admin/agents/overview.md:133 — Dale: positional-references 'the following icons above the data grid' describes physical UI placement, not a content cross-reference.
docs/threatprevention/8.1/admin/navigation/datagrid.md:44 — Dale: positional-references 'the Group by Box ribbon above the data grid' describes physical UI placement.
docs/threatprevention/8.1/admin/configuration/siemoutputviewer.md:73 — Dale: positional-references 'the Group by Box ribbon just above the header row' describes physical UI placement.
docs/threatprevention/8.1/reportingmodule/configuration/integrations/activedirectorysync.md:177 — Dale: positional-references 'dropdown menu above the right corner of the table' / 'Page navigation buttons are below the table' describe physical UI placement. Same pattern at systemsettings/auditing.md:38-39.
docs/threatprevention/8.1/reportingmodule/configuration/systemhealth.md:40 — Dale: positional-references 'an alert is displayed below the navigation header' describes physical UI placement.
docs/threatprevention/8.1/reportingmodule/investigations/newinvestigation.md:21 — Dale: positional-references 'the sections below the Filters section' describes physical UI placement.
docs/threatprevention/8.1/reportingmodule/investigations/options/filters.md:232 — Dale: positional-references 'the options above the Filters section' describes physical UI placement.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/activedirectorychanges.md:325 — Dale: positional-references 'displayed in orange text in the box below' describes physical UI placement within the Advanced Filter window. Same at lines 343 and 348.
docs/threatprevention/8.1/admin/templates/configuration/actions.md:108 — Dale: positional-references 'in the boxes below' describes physical UI placement within the window. Same at line 112.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/threatmanagerldap.md:44 — Dale: positional-references 'the other LDAP Monitoring event type in the list above' refers to a UI list; line 48 'the line below the last existing query filter' is also UI placement.
docs/threatprevention/8.1/troubleshooting/logging.md:99 — Dale: positional-references 'Move the rule above the catch-all rule' is a literal instruction about ordering in a config file, not a documentation cross-reference.
docs/threatprevention/8.1/admin/analytics/breachedpassword.md:48 — Dale: positional-references 'Failed Attempts preceding a successful login' is temporal, not spatial. Same at bruteforceattacks.md:54.
docs/threatprevention/8.1/admin/analytics/useraccounthacking.md:20 — Dale: positional-references 'failed logins below lockout thresholds' is a numeric comparison, not a spatial reference. Same at qradar/offenses.md:28 and activedirectorychanges.md:138/140.
docs/threatprevention/8.1/admin/policies/configuration/actions/netscript.md:141 — Dale: positional-references 'Enter code in method ScriptMain below' appears inside a fenced code block (sample script output). Same at line 292.
docs/threatprevention/8.1/admin/investigate/summaryfolders.md:42 — Dale: positional-references 'available below the report name' describes physical UI placement.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/lsassguardianprotect.md:114 — Dale: positional-references 'Use the buttons above the box' describes physical UI placement. Same at filesystemaccessanalyzer.md:130.
docs/threatprevention/8.1/reportingmodule/configuration/integrations/overview.md:9 — Dale: wordiness 'a variety of Netwrix products' carries meaning (breadth of integrations) rather than being filler; removing it would change the claim. Same at configuration/overview.md:15.
docs/threatprevention/8.1/admin/configuration/databasemaintenance/overview.md:101 — Dale: passive-voice 'all event data collected by the Active Directory Changes... Event Types' — the reduced passive keeps the event-data noun as the subject of a parallel five-item list; rewriting each entry would break the list's parallelism for no clarity gain.
docs/threatprevention/8.1/admin/analytics/overview.md:13 — Dale: passive-voice 'incidents triggered by events' is a reduced relative clause where the passive is the natural and most concise phrasing.
docs/threatprevention/8.1/admin/configuration/epesettings.md:247 — Dale: passive-voice 'a global setting used across all EPE policies' — reduced passive is idiomatic here and the actor is unimportant. Same at wordslist/substitutions sections.
docs/threatprevention/8.1/admin/agents/deploy/setoptions.md:76 — Dale: passive-voice 'When the Enable DNS Host Name Resolution option is enabled' — 'enabled' is adjectival/stative here (describing the option's state), not a true passive construction.
docs/threatprevention/8.1/admin/analytics/horizontalmovementattacks.md:64 — Dale: misplaced-modifiers 'If checked, the Ignore failed logins... option excludes...' — the modifier correctly attaches to 'the option', so it is not dangling. Same at bruteforceattacks.md:66, useraccounthacking.md:74, siemoutputviewer.md:38/40, authenticationmonitoring.md:76.
docs/threatprevention/8.1/requirements/ports.md:102 — Dale: misplaced-modifiers 'If a firewall or other appliance is blocking these ports, this server will...' — the conditional clause has its own explicit subject, so nothing dangles.
docs/threatprevention/8.1/gettingstarted.md:9 — Dale: misplaced-modifiers 'After launching the Threat Prevention Administration Console, the administrator must configure...' — the administrator is the one launching the console, so the participle attaches correctly.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/passwordenforcement.md:44 — Dale: wordiness Sentence contains a separate content defect ('Preventioncontains' — missing space) that is a typo rather than a Dale style issue; left for an editorial pass so the fix isn't buried in a style commit.
docs/threatprevention/8.1/admin/configuration/epesettings.md:217 — Dale: wordiness 'Use the Language dropdown menu to select a language, The Default Message column displays...' is a comma splice — a punctuation/grammar defect outside the Dale rule set, and splitting it could change the intended relationship between the clauses.
docs/threatprevention/8.1/admin/policies/configuration/eventtype/window/*.md:1 — Dale: passive-voice Bulk residual passive constructions across the 8.1 set (roughly 1,700 grep candidates) are dominated by stative UI descriptions ('is displayed', 'is enabled', 'is selected') where the passive is correct or the actor is genuinely unknown. Only unambiguous agent-bearing passives and dangling constructions were rewritten; blanket conversion would be a large-scale content rewrite beyond confident automated fixing.

Ask @claude on this PR if you'd like an explanation of any fix.

Adds 8.1 to threatprevention.versions, promotes it to isLatest, and
sets defaultVersion to 8.1. Without this, docs/threatprevention/8.1/
and sidebars/threatprevention/8.1.js are never picked up by the
Docusoraus plugin generation, navbar, or KB copy script.
…med ready

8.1 is now registered and reachable via the version switcher, but stays
isLatest: false so 8.0 remains the default landing version. Screenshots
still show the 8.0 UI and a few facts (Trusted Domains Blacklist menu
path, .log.config vs logconfig.xml naming, tab placement for the
unresolved-folder/unavailable-checksum options) came from a written
source rather than a verified build. Promote 8.1 to latest once those
are confirmed.
The PR intentionally leaves 8.1 out of products.js until release day —
per the PR description, this keeps the 296 new pages, screenshots (still
showing 8.0 UI), and a few unverified facts (Trusted Domains Blacklist
menu path, .log.config vs logconfig.xml naming, tab placement for the
unresolved-folder/unavailable-checksum options) completely unreachable
rather than just non-default. Registering 8.1 (even with isLatest:
false) would make it publicly browsable and indexed, which is more
exposure than intended. Registration remains a one-line change to make
when the release ships.
@hilram7

hilram7 commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Registered 8.1 in products.js per the earlier Code Review comment ("🔴 Blocking — 8.1 never gets built"), then reverted it. The PR description clarifies that leaving 8.1 unregistered is intentional. Registration remains a one-line change for release day.

hilram7
hilram7 previously approved these changes Sep 3, 2026
# Conflicts:
#	docs/threatprevention/8.1/admin/policies/configuration/eventtype/lsassguardianmonitor.md
#	docs/threatprevention/8.1/admin/policies/configuration/eventtype/lsassguardianprotect.md
# Conflicts:
#	docs/threatprevention/8.1/admin/policies/configuration/eventtype/lsassguardianmonitor.md
#	docs/threatprevention/8.1/admin/policies/configuration/eventtype/lsassguardianprotect.md
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

99 issues fixed, 48 skipped across 296 files

Category Fixes
OnceUsage (rewrite) 1
Spacing (rewrite) 1
TypeVsEnter (rewrite) 2
Dale: exclamatory-sentences 5
Dale: misplaced-modifiers 4
Dale: passive-voice 77
Dale: positional-references 1
Dale: wordiness 7
Dale: xy-slop 1
Skipped (needs manual review) Reason
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:22 — Netwrix.FirstPerson False positive — 'I will provide a list' is the literal UI label of an option button; rewording would misname the control
docs/threatprevention/8.1/admin/configuration/collectionmanager/dynamic.md:25 — Netwrix.FirstPerson False positive — 'I want a list to come from the database table' is the literal UI label of an option button
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:36 — Netwrix.FirstPerson False positive — 'I will provide a list' is the literal UI label of an option button
docs/threatprevention/8.1/admin/configuration/collectionmanager/listcollections.md:37 — Netwrix.FirstPerson False positive — 'I want a list to come from the database table' is the literal UI label of an option button
docs/threatprevention/8.1/admin/configuration/epesettings.md:9 — Netwrix.FirstPerson False positive — 'Have I Been Pwned (HIBP)' is a product/database proper noun
docs/threatprevention/8.1/admin/configuration/epesettings.md:134 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun used as a cross-reference topic title
docs/threatprevention/8.1/admin/configuration/epesettings.md:341 — Netwrix.FirstPerson heading text — not modified to avoid breaking anchor links (also a 'Have I Been Pwned' proper-noun false positive)
docs/threatprevention/8.1/admin/configuration/epesettings.md:348 — Netwrix.FirstPerson False positive — 'Have I Been Pwned (HIBP) database' is a proper noun
docs/threatprevention/8.1/admin/configuration/epesettings.md:350 — Netwrix.FirstPerson False positive — 'Have I Been Pwned' is the link text for haveibeenpwned.com
docs/threatprevention/8.1/admin/configuration/epesettings.md:371 — Netwrix.FirstPerson False positive — 'The Have I Been Pwned database (HIBP)' is a proper noun
docs/threatprevention/8.1/admin/configuration/systemalerting/email.md:35 — Netwrix.Please False positive — 'Select Profile, please' is the literal UI label of the option in the console
docs/threatprevention/8.1/admin/configuration/systemalerting/siem.md:37 — Netwrix.Please False positive — 'Select Profile, please' is the literal UI label of the dropdown menu
docs/threatprevention/8.1/admin/navigation/overview.md:50 — Netwrix.FirstPerson False positive — 'Alt+I' is a keyboard shortcut
docs/threatprevention/8.1/admin/navigation/overview.md:59 — Netwrix.FirstPerson False positive — 'Have I Been Pwned' is a proper noun
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemchanges/filesystemchanges.md:106 — Netwrix.FirstPerson False positive — 'I/O Type area' refers to the input/output abbreviation, not first person
docs/threatprevention/8.1/admin/policies/configuration/eventtype/filesystemlockdown.md:93 — Netwrix.FirstPerson False positive — 'I/O Type area' refers to the input/output abbreviation, not first person
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:32 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:34 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:35 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:39 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:51 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/ldapmonitoring/ldapping.md:54 — Netwrix.Repetition False positive — 'LDAP Nom Nom' is the name of a known attack tool
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/monitorweakpasswords.md:28 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun inside cross-reference link text
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/passwordenforcement.md:305 — Netwrix.FirstPerson False positive — 'Have I Been Pwned?' is a proper noun wrapped across lines
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/preventweakpasswords.md:24 — Netwrix.OxfordComma False positive — 'As a best practice, create and enable a monitoring policy' is a two-verb pair, not a series of three items; adding a comma would be wrong
docs/threatprevention/8.1/admin/policies/configuration/eventtype/passwordenforcement/preventweakpasswords.md:35 — Netwrix.FirstPerson False positive — 'Have I Been Pwned Hash List' is a proper noun inside cross-reference link text
docs/threatprevention/8.1/admin/tools/import.md:23 — Netwrix.FirstPerson False positive — 'Alt+I' is a keyboard shortcut
docs/threatprevention/8.1/eperestsite/accountmanagement.md:81 — Netwrix.QuestionHeadings heading text — not modified to avoid breaking anchor links (the '?' is part of the API query string 'api/account/delete?userName=')
docs/threatprevention/8.1/install/adminconsole.md:38 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal checkbox label
docs/threatprevention/8.1/install/agent/manual.md:57 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal checkbox label
docs/threatprevention/8.1/install/application.md:40 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal checkbox label
docs/threatprevention/8.1/install/eperestsite.md:36 — Netwrix.FirstPerson False positive — 'I accept the terms in the License Agreement' is the literal checkbox label
docs/threatprevention/8.1/install/reportingmodule/application.md:39 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal checkbox label
docs/threatprevention/8.1/install/reportingmodule/database.md:37 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal checkbox label
docs/threatprevention/8.1/install/upgrade/reportingmodule.md:42 — Netwrix.FirstPerson False positive — 'I accept the license agreement' is the literal checkbox label
docs/threatprevention/8.1/requirements/agent/agent.md:42 — Netwrix.FirstPerson False positive — 'Have I Been Pwnd (HIBP) database' is a proper noun
docs/threatprevention/8.1/requirements/application.md:55 — Netwrix.FirstPerson False positive — 'Have I Been Pwnd (HIBP) database' is a proper noun
docs/threatprevention/8.1/solutions/filesystem.md:28 — Netwrix.FirstPerson False positive — 'I/O Type Events' refers to the input/output abbreviation, not first person
docs/threatprevention/8.1/siemdashboard/qradar/offenses.md:46 — Dale: passive-voice passive clause inside a reference table cell describing an offense trigger condition; rewriting would break the parallel structure of the table column
docs/threatprevention/8.1/install/agent/silent.md:57 — Dale: passive-voice "are generated values" is a predicate adjective, not passive voice
docs/threatprevention/8.1/siemdashboard/threathunting/overview.md:86 — Dale: passive-voice reduced relative clause ("events that are generated as soon as Splunk starts receiving data"); rewriting would change emphasis without improving clarity
docs/threatprevention/8.1/admin/templates/folder/siem.md:0 — Dale: passive-voice product-string template tables list literal policy/template names; editing them would misstate the shipped product strings
docs/threatprevention/8.1/admin/policies/configuration/overview.md:0 — Dale: positional-references "above"/"below" refers to physical UI position in the console, not to other content in the topic
docs/threatprevention/8.1/admin/policies/configuration/eventtype/eventtype.md:0 — Dale: passive-voice state-descriptive copular constructions ("is enabled by default", "are grayed-out") describe UI state rather than an action with an actor
docs/threatprevention/8.1/troubleshooting/admonitorlogging.md:0 — Dale: undefined-acronyms acronym occurs only in heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/admin/configuration/trusteddomainsblacklist.md:0 — Dale: wordiness heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/admin/templates/folder/schemaconfiguration.md:0 — Dale: passive-voice heading text — not modified to avoid breaking anchor links
docs/threatprevention/8.1/siemdashboard/qradar/navigate/navigate.md:0 — Dale: wordiness "instigate" retained instead of "initiate" to preserve the author's original wording and stay consistent across the sibling dashboard topics

Ask @claude on this PR if you'd like an explanation of any fix.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Code Review

Scope: correctness only (config, routing, scripts, workflows, structural integrity of the copied tree). Content and prose style are left to the editorial workflow. No workflow, script, or src/config files are touched by this PR.

1. Vale autofix lowercased sentence and heading starts (introduced by this PR)

docs/threatprevention/8.1/eperestsite/login.md:7 is now # log in to EPE REST Service APIs. 8.0 has # Login to EPE REST Service APIs. The autofix applied the "Login" to "log in" verb correction to an H1, so the rendered page title starts lowercase and no longer matches the frontmatter title: "Login to EPE REST Service" on line 2. Suggested: # Log In to EPE REST Service APIs.

The same class of rewrite hit five files mid-sentence, after a <br /> inside table cells, where the autofix could not see it was a sentence boundary:

  • admin/templates/folder/activedirectory.md (7 rows) - <br />Utilizes built-In became <br />uses built-In
  • admin/templates/folder/bestpractices.md
  • admin/templates/folder/siem.md
  • admin/templates/folder/hipaa.md
  • install/reportingmodule/secure.md - <br />Make sure became <br />ensure

18 lines in total. The equivalent pattern occurs zero times anywhere in docs/threatprevention/8.0/, so these are regressions from the autofix commits in this PR rather than something inherited from the copy. Worth fixing here, since the style workflow is what produced them.

2. sidebar_position collision in admin/configuration/

docs/threatprevention/8.1/admin/configuration/trusteddomainsblacklist.md:4 sets sidebar_position: 100, the same value as admin/configuration/systemalerting/_category_.json:3 ("position": 100) in the same parent directory. Docusaurus does not error on a tie, it falls back to its own ordering, so the placement of the new page relative to System Alerting is incidental rather than chosen. Given userroles sits at 110, 120 looks like the intended slot.

3. Static assets ship even though 8.1 is unregistered

The PR description says none of this is published yet, which holds for the markdown: getActiveVersions() drives plugin generation and docPath is resolved per version (src/config/products.js:915), so docs/threatprevention/8.1/ is entirely inert until the version is registered. static/ is not filtered that way - Docusaurus copies it wholesale into the build output, so the ~700 files added under static/images/threatprevention/8.1/ become publicly fetchable at predictable URLs on the production site as soon as this reaches main.

Most are byte-identical copies of the 8.0 images, but four are not: admin/configuration/trusteddomainsblacklist.webp, admin/configuration/trusteddomainsblacklist_selecttrusts.webp, and updated versions of admin/policies/eventtype/processesmonitoring.webp and processesprotect.webp. Those show pre-release 8.1 UI. Flagging in case that matters before the release ships; if not, no action needed.


Verified clean

  • Registration and routing - src/config/products.js is unchanged, and the mid-PR register/revert pair (84568cef7 then fa0d1a68e) landed clean. The new sidebars/threatprevention/8.1.js is byte-identical to the 8.0 autogenerated stub and is simply unreferenced until registration.
  • KB copy pipeline - buildConfig() in scripts/copy-kb-to-versions.mjs iterates PRODUCTS, so 8.1 receives nothing and kb_allowlist.json is unaffected. No kb/ folder was accidentally committed into docs/threatprevention/8.1/.
  • Links - all 233 unique /docs/threatprevention/8.1/... targets resolve to real files. Only six differ from the 8.0 link set: the five new topics plus admin/configuration/systemalerting/eventlog.md, all of which exist.
  • Anchors - every anchored cross-link is present in both versions. Five headings changed text (the Do Not Ignore row, the upgrade-path headings, the login H1) and none has an inbound anchor link, so nothing breaks on build.
  • Images - static/images/threatprevention/8.1/ is a strict superset of the 8.0 tree, so every rewritten /images/threatprevention/8.1/... reference resolves.
  • MDX - no new hazards. Every angle-bracket occurrence in the new topics is inside a code fence, inside backticks, or escaped (\<path\>); the <ul>/<li>/<br /> usage in tables mirrors 8.0.
  • KB frontmatter - products: threatprevention matches the product id in products.js, which is the documented standard, and tags: [kb] matches 247 other KB articles. The 23 sibling threatprevention KB files still carrying threat-prevention are pre-existing and out of scope here.
  • Version strings - installer names are consistently updated (8.0.x to 8.1.x, and the stale 7.4 reference in install/agent/silent.md), and netwrix.com/go/siagent800zip to siagent810zip follows the established pattern. I cannot confirm that redirect resolves yet.
  • Secrets - no credentials, keys, or connection strings in the new content.

Pre-existing, inherited by the copy (not introduced here)

  • admin/templates/folder/activedirectory.md:18 has a duplicated sentence in one table cell (is Off for this policy.ensure the Exclude ...); the same duplication exists at 8.0 line 18.
  • troubleshooting/overview.md and troubleshooting/sqlserver.md both use sidebar_position: 60, as they do in 8.0.

🤖 Generated with Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

KB review: docs(threatprevention): add 8.1 documentation (PR #1472)

5 participants