1,005 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

Error Whille setting up SMTP Email V3 connection

Hi Team, I am configuring SMTP connection and getting below error Failed to create connection: { "error": { "code": 502, "source": "logic-apis-easteurope.azure-apim.net", "clientRequestId": "",…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-05T11:33:16.4333333+00:00
Disha Bodade 65 Reputation points
accepted 2024-04-30T05:59:05.1333333+00:00
Disha Bodade 65 Reputation points
1 answer One of the answers was accepted by the question author.

Missing permission 'Microsoft.OperationsManagement/register/action' on scope '/subscriptions/8c507d2e-37ef-4ae1-864f-fd05f45b3cdb' is required to add Microsoft Sentinel to the selected workspace

Hi I'm facing problem when I tried to subscribe to Microsoft Sentinel. When I tried to add Microsoft Sentinel to my desire workspace , this notification pops up. I do have the Owner and Security Administrator permission. Can someone please enlighten me…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2023-03-16T09:02:09.1466667+00:00
Muhammad Zariq Razali 20 Reputation points
commented 2024-04-29T15:31:47.4366667+00:00
John Munro 0 Reputation points
2 answers

How to optimize amount of data sent via LogsIngestionClient.upload operation

Hi, I am using logs ingestion client in python to upload data. My usecase is to read messages off of aws sqs and build payloads that can be sent via LogsIngestionClient client. I built a simple timer trigger function app that reads aws sqs for new…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
4,422 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-03-26T01:19:20.7733333+00:00
Ashwin Venkatesha 230 Reputation points
answered 2024-04-29T09:37:43.6133333+00:00
Pinaki Ghatak 2,405 Reputation points Microsoft Employee
1 answer

Sentinel Smart Deployment cannot push csv file to Azure DevOps

When I deploy content to sentinel using Azure DevOps, the content deploys successfully but when smart deployment enabled, it cannot push csv tracking file to Azure Repo with error [Warning] API call failed:…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-05T06:33:36.0033333+00:00
Ha Nguyen 0 Reputation points
commented 2024-04-25T09:59:08.7433333+00:00
Ha Nguyen 0 Reputation points
1 answer

Is there any oracle logs parser for azure sentinel we are not using oracle unified agent

Is there any oracle logs parser for azure sentinel we are not using oracle unified agent

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-24T15:01:07.1466667+00:00
Kumar, Deepak 16 Reputation points
commented 2024-04-25T06:37:16.0266667+00:00
Givary-MSFT 28,756 Reputation points Microsoft Employee
1 answer

Closure Comments getting wiped out from Sentinel Incidents

Hi, We have observed that closure comments updated on sentinel incidents are getting wiped out after some time. This issue is observed for some of the alerts detected by Microsoft Defender. Only the closure classification remain in the incident activity…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-16T15:23:45.8633333+00:00
Shivthare, Tejaswi 0 Reputation points
edited an answer 2024-04-22T13:09:55.23+00:00
Andrew Blumhardt 9,601 Reputation points Microsoft Employee
4 answers

Azure Active Directory data connector missing

Hello all, Something that I've done on the regular has stopped working. Before reaching out to support, wondering if settings have just moved somewhere.. Basically trying to add the Azure Active Directory data connector to a Sentinel instance. Usually…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,952 questions
asked 2023-10-31T05:14:42.8466667+00:00
Courtney Cowling - ParaFlare 0 Reputation points
commented 2024-04-18T11:12:20.9166667+00:00
Michael Kirst-Neshva 0 Reputation points
1 answer One of the answers was accepted by the question author.

This offer is not available for subscriptions from Microsoft Azure Cloud Solution Providers

Hello There, In the latest sentinel news, a new solution has appeared, which is in preview, I would like to ask a question regarding the deployment of this solution, in sentinel there is a new option below the Content Management called Content Hub, and…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2021-11-11T15:36:23.22+00:00
Daniel Candela 21 Reputation points
commented 2024-04-18T01:29:23.1066667+00:00
Matthew McKenzie 0 Reputation points
1 answer

azure sentinel for aws log

I'm having issues importing AWS logs into Azure Sentinel. There are no issues importing data using data connectors, but I want to manually import tables that are not supported by data connectors in JSON format. I tried using Custom Log Data Collection…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-17T10:25:33.4666667+00:00
홍원종 Azure SA 0 Reputation points
answered 2024-04-17T20:32:31.13+00:00
Marilee Turscak-MSFT 35,116 Reputation points Microsoft Employee
1 answer

Analytic Rule -Which time prevails, Lookup data from the last or set in query?

I have a question regarding the search times when configuring a new alert and I don't know which time predominates, the one that is put in the query or the one that is set at the level of the alert configuration. Let's take the following query as an…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-11T11:15:46.35+00:00
Eduardo Vilar 0 Reputation points
commented 2024-04-16T13:23:24.5933333+00:00
Givary-MSFT 28,756 Reputation points Microsoft Employee
0 answers

Remove a mobile device from a user

Anyone has built a sentinel playbook / logic app to be able to remove active sync device from a user? And could share some details on how this was done?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,952 questions
asked 2023-07-02T21:27:54.2933333+00:00
Someread87 0 Reputation points
commented 2024-04-16T10:05:59.3566667+00:00
Fiona Matu 86 Reputation points Microsoft Employee
1 answer

IIS Log DCR via AMA is not collecting X-Forwarded-For column

Does Microsoft have a plan to include X-Forwarded-For data when collecting IIS logs for Azure Monitor or Sentinel?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,885 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-16T04:00:36.39+00:00
AdamKlocek-3110 40 Reputation points
answered 2024-04-16T06:00:45.9733333+00:00
Stanislav Zhelyazkov 21,521 Reputation points MVP
1 answer One of the answers was accepted by the question author.

Unable to take Applied Skills Assessments

This assessment is currently disabled due to a technical issue. Explore our other Applied Skills while we work on a fix. - Configure SIEM security operations using Microsoft Sentinel

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-03-24T05:29:15.59+00:00
Rath, Sibananda 50 Reputation points
commented 2024-04-15T17:58:16.1766667+00:00
Edward Hurtado 0 Reputation points
1 answer One of the answers was accepted by the question author.

The Address you provided is invalid, please provide a valid address and try again!!!

Hi, While I was trying to schedule the SC-200 Exam, I got the error message that the billing address isn't valid. How can I fix this issue. Thanks! Best Regards, Jasmina Jakob

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
163 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
113 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2024-04-12T19:23:56.8333333+00:00
Anonymous
accepted 2024-04-13T12:24:56.7366667+00:00
Anonymous
2 answers

Sentinel - Teams Playbook

Hi, I'm working on setting up a simple playbook to receive notifications for new incidents created in Sentinel, with an option to assign the incident. I've created an adaptive card (see below) and set up the playbook based on the instructions in a blog…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-09T07:29:27.5933333+00:00
Someiah C S 60 Reputation points
answered 2024-04-12T15:48:50.3466667+00:00
Andrew Blumhardt 9,601 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Azure Activity - data connector prerequisites

Hi all, When trying to enable the azure Acitvity connector in sentinal it says: I am am owner of the subscription already?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-08T12:52:17.6133333+00:00
Aran Billen 701 Reputation points
accepted 2024-04-12T10:17:28.0666667+00:00
Aran Billen 701 Reputation points
1 answer One of the answers was accepted by the question author.

Azure Workbook merge query visualization

I have created an Azure Workbook with a merge query that combines two table sources. This produces a nice table of resources (in this case, a list of VM's). Now all I want to do is somehow summarize this merged table and get the total number of VM's…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,885 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2022-02-09T10:58:43.327+00:00
René 26 Reputation points
commented 2024-04-11T09:37:50.3566667+00:00
Moritz von Witzleben 0 Reputation points
1 answer One of the answers was accepted by the question author.

How can I integrate GuardDuty findings with Microsoft Sentinel?

GuardDuty - Sentinel Integration

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2024-04-08T13:05:13.9266667+00:00
Johnstone Oloo 20 Reputation points
edited a comment 2024-04-10T19:13:07.72+00:00
Johnstone Oloo 20 Reputation points
3 answers One of the answers was accepted by the question author.

Error in Azure Sysmon Workbook project' operator: Failed to resolve table or column expression named 'process_create_whitelist

Hello everyone. I have been trying to set up a lab on my Azure Sentinel tenant to receive sysmon logs. I have followed some of the tutorials posted using the agents. Everything seem to work fine I am receiving logs from sysmon to azure, but where I…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,885 questions
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,913 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,107 questions
asked 2022-03-26T01:43:54.167+00:00
Alvarado, Peter 21 Reputation points
commented 2024-04-10T16:36:31.4433333+00:00
Adam Jakubiec 0 Reputation points
1 answer

I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel

I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel. Can someone please help me with steps\document.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2021-09-10T10:52:29.587+00:00
Singh, Sushmita[Non-Employee] 6 Reputation points
commented 2024-04-10T07:27:26.46+00:00
adewale Yusuf 0 Reputation points