Error Whille setting up SMTP Email V3 connection
Hi Team, I am configuring SMTP connection and getting below error Failed to create connection: { "error": { "code": 502, "source": "logic-apis-easteurope.azure-apim.net", "clientRequestId": "",…
Missing permission 'Microsoft.OperationsManagement/register/action' on scope '/subscriptions/8c507d2e-37ef-4ae1-864f-fd05f45b3cdb' is required to add Microsoft Sentinel to the selected workspace
Hi I'm facing problem when I tried to subscribe to Microsoft Sentinel. When I tried to add Microsoft Sentinel to my desire workspace , this notification pops up. I do have the Owner and Security Administrator permission. Can someone please enlighten me…
How to optimize amount of data sent via LogsIngestionClient.upload operation
Hi, I am using logs ingestion client in python to upload data. My usecase is to read messages off of aws sqs and build payloads that can be sent via LogsIngestionClient client. I built a simple timer trigger function app that reads aws sqs for new…
Sentinel Smart Deployment cannot push csv file to Azure DevOps
When I deploy content to sentinel using Azure DevOps, the content deploys successfully but when smart deployment enabled, it cannot push csv tracking file to Azure Repo with error [Warning] API call failed:…
Is there any oracle logs parser for azure sentinel we are not using oracle unified agent
Is there any oracle logs parser for azure sentinel we are not using oracle unified agent
Closure Comments getting wiped out from Sentinel Incidents
Hi, We have observed that closure comments updated on sentinel incidents are getting wiped out after some time. This issue is observed for some of the alerts detected by Microsoft Defender. Only the closure classification remain in the incident activity…
Azure Active Directory data connector missing
Hello all, Something that I've done on the regular has stopped working. Before reaching out to support, wondering if settings have just moved somewhere.. Basically trying to add the Azure Active Directory data connector to a Sentinel instance. Usually…
This offer is not available for subscriptions from Microsoft Azure Cloud Solution Providers
Hello There, In the latest sentinel news, a new solution has appeared, which is in preview, I would like to ask a question regarding the deployment of this solution, in sentinel there is a new option below the Content Management called Content Hub, and…
azure sentinel for aws log
I'm having issues importing AWS logs into Azure Sentinel. There are no issues importing data using data connectors, but I want to manually import tables that are not supported by data connectors in JSON format. I tried using Custom Log Data Collection…
Analytic Rule -Which time prevails, Lookup data from the last or set in query?
I have a question regarding the search times when configuring a new alert and I don't know which time predominates, the one that is put in the query or the one that is set at the level of the alert configuration. Let's take the following query as an…
Remove a mobile device from a user
Anyone has built a sentinel playbook / logic app to be able to remove active sync device from a user? And could share some details on how this was done?
IIS Log DCR via AMA is not collecting X-Forwarded-For column
Does Microsoft have a plan to include X-Forwarded-For data when collecting IIS logs for Azure Monitor or Sentinel?
Unable to take Applied Skills Assessments
This assessment is currently disabled due to a technical issue. Explore our other Applied Skills while we work on a fix. - Configure SIEM security operations using Microsoft Sentinel
The Address you provided is invalid, please provide a valid address and try again!!!
Hi, While I was trying to schedule the SC-200 Exam, I got the error message that the billing address isn't valid. How can I fix this issue. Thanks! Best Regards, Jasmina Jakob
Sentinel - Teams Playbook
Hi, I'm working on setting up a simple playbook to receive notifications for new incidents created in Sentinel, with an option to assign the incident. I've created an adaptive card (see below) and set up the playbook based on the instructions in a blog…
Azure Activity - data connector prerequisites
Hi all, When trying to enable the azure Acitvity connector in sentinal it says: I am am owner of the subscription already?
Azure Workbook merge query visualization
I have created an Azure Workbook with a merge query that combines two table sources. This produces a nice table of resources (in this case, a list of VM's). Now all I want to do is somehow summarize this merged table and get the total number of VM's…
How can I integrate GuardDuty findings with Microsoft Sentinel?
GuardDuty - Sentinel Integration
Error in Azure Sysmon Workbook project' operator: Failed to resolve table or column expression named 'process_create_whitelist
Hello everyone. I have been trying to set up a lab on my Azure Sentinel tenant to receive sysmon logs. I have followed some of the tutorials posted using the agents. Everything seem to work fine I am receiving logs from sysmon to azure, but where I…
I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel
I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel. Can someone please help me with steps\document.