1,005 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer

Powershell Script to add connectors to Azure Sentinel

Hi Team, Is there any way to automate the process(powershell or Json scripts/code) to add following data connectors to sentinel. -Azure Active Directory -Azure Activity -Azure Security Centre -Security Events I did not get any commands/code…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-09-14T11:29:43.873+00:00
Ankush Chauhan 1 Reputation point
commented 2020-09-25T23:42:30.85+00:00
JamesTran-MSFT 36,486 Reputation points Microsoft Employee
1 answer

Sentinel 'Events and alerts over time' graph

Hi all, Let me start by thanking you in advance and being honest that I am very new to Sentinel. I've deployed a few Windows Firewall Data Connectors, Over the past few hours. However, the graph under the 'Workspace' for these machines looks odd.…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-09-22T15:00:06.283+00:00
Niall Quinn 1 Reputation point
commented 2020-09-25T23:41:43.053+00:00
JamesTran-MSFT 36,486 Reputation points Microsoft Employee
0 answers

Azure Sentinel - Active Directory Connector show different info about log-ins than Azure Active Directory logs in

Yesterday I've chatted with Microsoft's support engineer from the "new support request" in our Log Analytics workspace. The engineer suggested me to write a question here. My issue is: when I go to my Azure Active Directory >…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,951 questions
asked 2020-08-27T09:48:08.057+00:00
Davide-IT 1 Reputation point
commented 2020-09-02T10:26:37.887+00:00
Davide-IT 1 Reputation point
1 answer

Email/Phone Indicators in Account Entity Types

Hi There, As Sentinel supports only four entity types - Account 2. IP 3. Host 4. URL Can we use Email or Phone Number in the logs and map it to Account Entity Type?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-08-18T13:23:07.837+00:00
Venkat Rambatla 1 Reputation point
commented 2020-08-25T22:56:16.797+00:00
JamesTran-MSFT 36,486 Reputation points Microsoft Employee
2 answers

Behavior Analytics

Hello All, Kindly any one give me some details about behavior analytics. If i enable it then what is the benefit of this service. Is this chargeable?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-08-23T05:54:32.34+00:00
Rohit 1 Reputation point
answered 2020-08-25T22:08:01.323+00:00
Saurabh Sharma 23,766 Reputation points Microsoft Employee
0 answers

possible query to filter data from PCAP in Sentinel.

What would be possible query to capture the pcap data in sentinel.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-08-19T13:58:16.333+00:00
Uma 1 Reputation point
commented 2020-08-21T17:08:38.607+00:00
Saurabh Sharma 23,766 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Can Azure Sentinal be used for any scenario when we migrate data from ADLS Gen1 to Gen2

We are using Data factory to migrate data (mostly files in form of parquet) from ADLS Gen1 to ADLS Gen2. I am aware that Azure sential can be used for thread detection, protection etc using the Incidents raised. But can this be used only for this data…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-08-07T12:40:16.34+00:00
Vaibhav Chaudhari 38,661 Reputation points
accepted 2020-08-19T14:45:28.08+00:00
Vaibhav Chaudhari 38,661 Reputation points
0 answers

creating additional/custom fields in "CommonSecurityLog" currently stored as e.g. "DeviceCustomString1"

Hi, how can we achieve creating additional fields for logs being processed in "CommonSecurityLog" (https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/commonsecuritylog)? At the moment incoming data gets mapped to fields…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-08-10T11:38:08.54+00:00
Peter Schönegger 21 Reputation points
commented 2020-08-12T18:17:36.343+00:00
Marilee Turscak-MSFT 35,116 Reputation points Microsoft Employee
2 answers

Turning off Azure Security Centre to cut monthly operations cost

How much does it cost for the Azure Security Centre access per month? My security team has already deployed IBM Q-Radar SIEM and wanted to cut the cost of operating Azure cloud, hence I wonder: How much does it cost monthly to run Azure Security…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,228 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,951 questions
asked 2020-07-22T07:41:07.79+00:00
EnterpriseArchitect 4,896 Reputation points
commented 2020-08-01T10:27:48.307+00:00
Ken Golitin 21 Reputation points
1 answer

How to take the Network Security Group(NSG) logs to Azure Sentinel

Hello, I have Azure Sentinel, Kindly suggest the steps how to forward the NSG(Azure Firewall) logs to Sentinel. Regards, Chandan Prajapati

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
582 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-18T19:15:54.85+00:00
Anonymous
commented 2020-07-30T23:00:48.757+00:00
Marilee Turscak-MSFT 35,116 Reputation points Microsoft Employee
2 answers

Window Firewall

Hello All, Kindly suggest me how to take the Windows Firewall logs to Sentinel. Thank You

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,786 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-23T06:19:36.093+00:00
Rohit 1 Reputation point
commented 2020-07-29T07:41:36.12+00:00
Cherry Zhang (Shanghai Wicresoft) 11 Reputation points
1 answer

Is it possible to display Sentinel Incidents and Alerts within Azure Dashboards

Hi, I am wondering if i can query the SecurityAlert logs within Dashboard query? I find the workbooks and the Sentinel Overview screen to not be ideal as a dashboard screen and want to have it all in dashboards

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-22T01:13:08.123+00:00
Cal 1 Reputation point
commented 2020-07-27T21:01:10.917+00:00
JamesTran-MSFT 36,486 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

What's the best way to get on-premise Domain Controller Logs into Sentinel?

I'm working to get logs from an on-prem server into Sentinel. Really all I need is visibility into what's going on, and some route to respond to threats so it doesn't necessarily have to be Sentinel but that's what I've been using so far to monitor Azure…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-23T15:17:53.777+00:00
Sam C 46 Reputation points
commented 2020-07-23T19:24:37.28+00:00
Sam C 46 Reputation points
2 answers

Nsg Log to Sentinel

Hello, Can any one provide me the exact process/Docs/link for how to enable Azure Firewall(NSG) to Sentinel. Or how to see the (Azure Firewall) NSG logs in Sentinel. Thanks Rohit

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
582 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-20T07:14:04.533+00:00
Rohit 1 Reputation point
commented 2020-07-21T16:21:55.867+00:00
Rohit 1 Reputation point
2 answers

Where is the appliance name/ip when sending Fortigate (CEF) logs to Sentinel?

I have two different fortigate that stream logs to a CEF collector (linux oms agent). The agent relays the info to logs analytics workspace that has azure sentinel and it does process them. When querying the logs I do not have a way to know from which…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,885 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-06-11T04:27:53.417+00:00
Juan Orjuela 1 Reputation point
commented 2020-07-20T15:30:50.527+00:00
Saurabh Sharma 23,766 Reputation points Microsoft Employee
0 answers

Getting a 500 error when creating a office 365 dataconnector by using the azure api.

Hello, I'm trying to replicate this example and I'm getting a 500 error. Does anybody has faced this same issue before? …

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
1,826 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-07-17T04:57:31.91+00:00
Camilo 1 Reputation point
commented 2020-07-18T00:16:47.253+00:00
Saurabh Sharma 23,766 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Is it possible to create an alert in Azure Sentinel for when a data source stops feeding logs?

I am trying to create an alert query that will let me know if a specific source has not provided logs within 7 days, but I am not sure the what syntax would allow for this. It is simple to find entries older than 7 days, but is it possible to alert if…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,885 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-06-18T16:10:30.507+00:00
Corey 21 Reputation points
commented 2020-06-18T16:36:57.77+00:00
Corey 21 Reputation points
2 answers

AI for Covid19

In today's crisis of Covid19, AI will definitely is a key element to be used to further enhance humanity and health of the world. What would be the best technology to be used?

Azure AI Speech
Azure AI Speech
An Azure service that integrates speech processing into apps and services.
1,456 questions
Azure AI Personalizer
Azure AI Personalizer
An Azure artificial intelligence service that enables applications to personalize user experiences by learning from collective real-time user behavior.
32 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-06-13T16:23:12.55+00:00
Mulia Dewi Karnadi 1 Reputation point
answered 2020-06-15T12:00:02.453+00:00
romungi-MSFT 42,986 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Looking for a sample event that triggers when one of the existing users has been assigned with "global admin privilege" in office 365

On the SIEM solution (eg. Azure sentinel), i am looking to create a correlation rule that will use the event that gets generated when one of the existing users has been assigned with the 'global admin' privileges. As i do not have any such instances from…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-06-11T11:03:17.133+00:00
Venkatesh 36 Reputation points
accepted 2020-06-14T21:29:04.38+00:00
Venkatesh 36 Reputation points
2 answers One of the answers was accepted by the question author.

What happens after free trial for Azure Sentinel expires and what are the trial limits?

Our client wants to try trial version of Azure Sentinel and is curious what happens after free trial expires, for example, will he lose access to all features or will he have access to partial free features or he'll have access but will pay per usage. …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,005 questions
asked 2020-06-01T13:31:22.81+00:00
groupireum 21 Reputation points
commented 2020-06-02T22:48:51+00:00
Saurabh Sharma 23,766 Reputation points Microsoft Employee