1,048 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

How to retrieve output data after the deployment

Hello there, I am wondering if there's a straightforward method to retrieve the output results after a deployment is completed. By 'straightforward,' I mean configuring a specific API-link during the deployment to which the output data, along with its…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-09T02:00:48.7+00:00
LXF 180 Reputation points
accepted 2024-07-15T05:58:10.1766667+00:00
LXF 180 Reputation points
3 answers

Export Logs from Log Analytics Workspace to Blob Storage

Hi all, I have a Log Analytics Workspace that is linked to Sentinel. I have a lot of logs that I need to export from the Workspace into Blob Storage. Th logs date back 30 days and it is about 400GB, it is about 500 million logs. Please let me know what…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,599 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-11T12:37:19.9733333+00:00
Adriaan Boshoff 0 Reputation points
commented 2024-07-12T10:40:36.3+00:00
Adriaan Boshoff 0 Reputation points
2 answers One of the answers was accepted by the question author.

Azure Sentinel Log Screen KQL mode to start by default

Azure Sentinel changed about a month ago the Log page GUI. It added a default Simple Mode, which does not seem to allow to enter KQL query by typing. The KQL mode, much more practical, needs to be selected over and over in the right side of the screen.…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-10T11:05:41.85+00:00
Jan Stodola 56 Reputation points
commented 2024-07-11T21:03:24.02+00:00
Jan Stodola 56 Reputation points
0 answers

Sentinel _BilledSize and estimate_data_size differences

hey folks Could somebody tell me the relationship between the _BilledSize field in a log and the result of the estimate_data_size(*) KQL command? I do understand that the _BilledSize field contains the info of the size of the data I have to pay for…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-07T14:02:15.47+00:00
Sándor Tőkési 181 Reputation points
commented 2024-07-11T09:16:11.9366667+00:00
Sándor Tőkési 181 Reputation points
1 answer

ActionConditionFailed The execution of template action 'Get_user' is skipped: there are no items to repeat.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-03T20:49:14.5+00:00
A Amir Shaltami 0 Reputation points
edited the question 2024-07-11T07:14:02.17+00:00
VarunTha 5,730 Reputation points Microsoft Vendor
1 answer

Can not enable MSD Threat Intelligence Data Connector

I have a cx that is getting the error below when attempting to enable Microsoft Defender Threat Intelligence data connector. He is using the (Preview) version. What could be causing this?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-09T23:56:42.1833333+00:00
DG001 386 Reputation points Microsoft Employee
answered 2024-07-11T06:49:15.7833333+00:00
Givary-MSFT 30,441 Reputation points Microsoft Employee
1 answer

Segregating and Identifying Alerts in Sentinel Workspace

I am seeking a method to segregate alerts in a Sentinel workspace to facilitate easier identification and prioritization. For instance, if we have multiple clients' logs in a single workspace, we need a way to identify and segregate alerts based on the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-03T04:32:08.67+00:00
Someiah C S 80 Reputation points
commented 2024-07-11T04:12:27.13+00:00
Givary-MSFT 30,441 Reputation points Microsoft Employee
1 answer

Sentniel free data sources

Hi, quoting from https://learn.microsoft.com/en-us/azure/sentinel/billing?tabs=commitment-tier#free-data-sources "The following data sources are free with Microsoft Sentinel: Azure Activity Logs. Office 365 Audit Logs, including all…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2022-09-13T13:01:19.587+00:00
AdamBudziski-8216 16 Reputation points
commented 2024-07-10T05:16:14.0833333+00:00
EnterpriseArchitect 5,116 Reputation points
0 answers

Sentinel to azure firewall connection issues

I am having issues connecting sentinel to azure firewall. I have establish 9 other connections no problem but not to the azure firewall from sentinel data connector. I have rebuilt the firewall several times, I confirmed the diagnostic log setting and…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-09T18:44:56.13+00:00
Sapphire BLU 0 Reputation points
edited the question 2024-07-10T03:54:23.1166667+00:00
KapilAnanth-MSFT 40,256 Reputation points Microsoft Employee
0 answers

CloudWatch ASIM Parser

I have successfully connected AWS CloudWatch to Sentinel, and I am receiving events from multiple log groups. However, I am facing an issue with parsing the events, particularly with the 'Message' field that is in JSON format. Currently, the 'Message'…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-01-16T09:26:19.8533333+00:00
LS 20 Reputation points
commented 2024-07-09T22:21:18.2633333+00:00
Brian Bye 0 Reputation points
1 answer

Sentinel as IaC with Terraform

Hi, Trying to instantiate Sentinel using Terraform. Should be straightforward, create a resource group (azurerm_resource_group), log analytics workspace (azurerm_log_analytics_workspace), onboarding Sentinel…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2023-08-23T05:55:02.6333333+00:00
AdamBudzinskiAZA-0329 91 Reputation points
answered 2024-07-09T12:49:59.4766667+00:00
Eduardo Perez 0 Reputation points
1 answer

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use?

Due to the scoring of MDCA being discontinued, if we need to retain the TOP 10 users using UEBA, what methods can we use? 'Investigation priority score' feature and 'Investigation priority score increase policy' will be phased out in the coming weeks,…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
119 questions
asked 2024-06-20T09:25:17.94+00:00
Koonnamchok Klongkaew 140 Reputation points
commented 2024-07-09T02:21:53.6533333+00:00
Koonnamchok Klongkaew 140 Reputation points
1 answer

Minimum hardware requirements for installation of AMA via ARC on Servers

Hello Community. Having a bit of a hard time trying to find the minimum hardware requirements for Windows and Linux Servers for the installation of AMA via ARC. I'm looking for something similar that I found with MDE like this. MDE Minimum…

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
375 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-08T19:38:00.3166667+00:00
Chris 0 Reputation points
answered 2024-07-08T21:58:34.15+00:00
Marcin Policht 17,615 Reputation points MVP
3 answers One of the answers was accepted by the question author.

Ingesting Cisco ASA logs into Sentinel using the AMA agent

Hi there, We are looking to onboard Cisco ASA logs into Microsoft Sentinel. Currently the Cisco ASA integration guide (linked below) on Microsoft Docs is referencing using the old MMA agent to get these logs onboarded. As this agent is being deprecated…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,987 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2023-07-11T14:18:52.23+00:00
Stephen Crooks 20 Reputation points
answered 2024-07-07T23:15:58.16+00:00
Peter Cronwright 6 Reputation points
1 answer

DataConnector connectorUI attributes - sampleQueries

hey folks, I was working on some data connectors and seemingly some of the old features are not working anymore. I tried to use some fields which seem to be dated now. The most relevant would be the 'sampleQueries' attribute. I remember having these in…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-06-10T08:25:05.6566667+00:00
Sándor Tőkési 181 Reputation points
commented 2024-07-07T11:46:08.5433333+00:00
Sándor Tőkési 181 Reputation points
0 answers

Regarding None Accounts Adding to Security Enabled Local, Global and Universal Groups

Hello Team, Greetings!! During our monitoring activities in Sentinel, we have observed that some non-accounts have been added to security-enabled local, global, and universal groups. Could you please provide insight into why this activity is being…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-07-03T16:54:11.04+00:00
Srisaiteja Palle 20 Reputation points
commented 2024-07-05T15:57:06.93+00:00
Srisaiteja Palle 20 Reputation points
1 answer One of the answers was accepted by the question author.

Find creation date of custom analytical rule created in Sentinel

Hi all, I am aiming to find the number of new analytical rules created per month (including custom as well as from github deployed), as well as the existing total per month on Sentinel for the last 2 months and present it to a Sentinel workbook. How…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-06-21T13:16:42.7966667+00:00
Ev s 20 Reputation points
accepted 2024-07-03T12:21:03.83+00:00
Ev s 20 Reputation points
2 answers One of the answers was accepted by the question author.

How to disconnect Azure Sentinel data connectors?

In Sentinel I cant able to find an option to disconnect the data connectors . And there are no documents available for the same. So what are the methods to disconnect a data connector inside sentinel for both native and non native products. When I…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-06-28T16:23:07.86+00:00
RAHUL MP 20 Reputation points
accepted 2024-07-03T11:55:28.2166667+00:00
RAHUL MP 20 Reputation points
1 answer

Stop Creating Incidents in Sentinel For every Alert generated by Custom detection rule in defender for endpoint

Hi Team, I have created a custom rule in Defender with KQL query to get the details about Device & owners of Vulnerable machines. So results are having rows more than 1500, and its generating that many alerts in defender. And same events are getting…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
asked 2024-06-25T17:06:28.82+00:00
Disha Bodade 65 Reputation points
commented 2024-07-03T05:50:47.05+00:00
Disha Bodade 65 Reputation points
0 answers

API Version Discrepancies for 'Data Connector Definitions' in Sentinel

Hello MS Community, Would you please help explain the discrepancy regarding API references to "data connector definitions"? I noticed the API related link…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,048 questions
Azure Startups
Azure Startups
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.Startups: Companies that are in their initial stages of business and typically developing a business model and seeking financing.
237 questions
asked 2024-06-14T08:30:15.17+00:00
LXF 180 Reputation points
edited the question 2024-07-03T04:22:40.0133333+00:00
Ryan Hill 26,946 Reputation points Microsoft Employee