135 questions with Microsoft Sentinel tags

Sort by: Created
0 answers

API Version Discrepancies for 'Data Connector Definitions' in Sentinel

Hello MS Community, Would you please help explain the discrepancy regarding API references to "data connector definitions"? I noticed the API related link…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-14T08:30:15.17+00:00
LXF 120 Reputation points
0 answers

Syslog through AMA (CEF) Connector

Hi, Follwing up on my last question: https://learn.microsoft.com/en-us/answers/questions/1690671/syslog-through-ama-connector-not-showing-in-the-co I have now installed Arc, and the machine is showing up on Azure Arc. The AMA is installed and is…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,922 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-11T10:30:54.9766667+00:00
Bl()e 0 Reputation points
commented 2024-06-14T10:14:19.01+00:00
Graham Bloice 0 Reputation points
0 answers

how Azure ARM templates process placeholders please?

Could you explain how Azure ARM templates process placeholders and variables during deployment, especially comparing the '[variables]' syntax with templating mechanisms like {{variables}}? I see some of the codes (from Sentinel Solution folder @ github)…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-11T02:47:43.6333333+00:00
LXF 120 Reputation points
commented 2024-06-11T10:06:35.52+00:00
Akshay-MSFT 16,926 Reputation points Microsoft Employee
0 answers

DataConnector connectorUI attributes - sampleQueries

hey folks, I was working on some data connectors and seemingly some of the old features are not working anymore. I tried to use some fields which seem to be dated now. The most relevant would be the 'sampleQueries' attribute. I remember having these in…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-10T08:25:05.6566667+00:00
Sándor Tőkési 181 Reputation points
commented 2024-06-11T14:53:19.3366667+00:00
Sándor Tőkési 181 Reputation points
0 answers

logo size for Sentinel Content Preparation

Hello, I am preparing the Sentinel content according to the following steps from github, my question is if there's requirement about the size of the logo? Thanks.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-03T09:35:57.3066667+00:00
LXF 120 Reputation points
commented 2024-06-03T19:11:38.1266667+00:00
Marilee Turscak-MSFT 35,541 Reputation points Microsoft Employee
0 answers

Syslog Transformation DCR not working

I need assistance troubleshooting a Syslog Transformation DCR used with Microsoft Sentinel. The Transformation DCR looks to work correctly in the Create Transformation wizard, but doesn't actually filter out the records. I have a few Syslog/CEF…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,922 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-29T16:03:21.6833333+00:00
Greg Sneed 0 Reputation points
commented 2024-06-14T10:23:33.5133333+00:00
AnuragSingh-MSFT 20,986 Reputation points
0 answers

Sentinel - Sophos Endpoint Protection (using REST API) (Preview) - Fails due to trying to create a table with a hyphen!

When trying to configure and deploy the new Sophos API connector for Sentinel it fails. Looks like it's trying to create a new table called Custom-SophosEPAlerts_CL but tables cannot contain hyphens so needs changing to CustomSophosEPAlerts_CL…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-22T09:34:28.36+00:00
James Grant 0 Reputation points
commented 2024-05-28T12:43:58.3066667+00:00
Andrew Blumhardt 9,676 Reputation points Microsoft Employee
0 answers

Extensions AMA - Impossible to install agent

Hello, I'm trying to deploy an AMA extension but I m stuck in "creating" with the following error messages from the Guestconfig file on a RHEL 9 linux servers: [2024-05-15 15:52:30.135] [PID 1117] [TID 1629] [Pull Client] [INFO] Successfully…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-15T14:42:38.4966667+00:00
Christophe Rosenkranz 5 Reputation points
edited the question 2024-05-16T19:09:30.2466667+00:00
Christophe Rosenkranz 5 Reputation points
0 answers

Query set to run in my Logic App is timing out and failing

Hello everyone. I am trouble shooting an issue with my Logic App in which after an incident triggers, the next step is to run the query and list the results, but this part of the Logic App is what is timing out and failing. When reading the timeout…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,931 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-21T13:17:52.54+00:00
Matthew Agosta 0 Reputation points
edited a comment 2024-04-03T09:27:33.3133333+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Microsoft Defender for Office 365 (0/5 connected)​ : In Defender XDR connector, Office 365 logs cannot be connected in Sentinel.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-19T15:18:44.7266667+00:00
Mohammad Sayeem Chowdhury 0 Reputation points
commented 2024-03-20T09:10:54.34+00:00
Givary-MSFT 29,341 Reputation points Microsoft Employee
0 answers

Cannot view Sentinel alert for some incidents but the alert can be found in Defender for Endpoint portal using Graph

I have enabled automatic incident creation for Defender for Endpoint in Sentinel but when I try to view some alerts associated with the created incidents, nothing is displayed. Despite this, I can locate the relevant alert in the Security (Defender for…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,049 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-12T07:17:33.5466667+00:00
Spyros Ermogenous 0 Reputation points
commented 2024-03-15T12:24:32.9766667+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Getting Error while saving Analytics rule as "the provided 'productFilter' was not recognized as a valid product"

Team, I am trying to Create Analytics Rule, Also created a Automation Rule with default options and created one playbook to run n action of that automation rule. But while Saving the Analytics Rule, Sentinel through below error. Failed to save analytics…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-11T12:43:30.48+00:00
Disha Bodade 65 Reputation points
commented 2024-03-12T10:42:29.35+00:00
Akshay-MSFT 16,926 Reputation points Microsoft Employee
0 answers

Sentinel widgets and private endpoint

Do the widgets and Insights works Incidents panel in Sentinel when the Log Analytics Workspace uses private endpoints? "externaldata operator"…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-28T15:28:28.55+00:00
Peter Fischer 1 Reputation point
commented 2024-02-28T18:10:15.7966667+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Playbook ARM template generator broken

Hey, I have been using the playbook ARM template generator for years and the past week it does not work at all. It tries to log into local host to present the portal but it does not work correctly. I have tried it on 3 machines and several browsers. …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-24T08:56:37.66+00:00
Cloudsec 150 Reputation points
commented 2024-03-06T03:13:17.03+00:00
Andrew Blumhardt 9,676 Reputation points Microsoft Employee
0 answers

Microsoft SentinelCEF Installer

I have tried installing cef installer on linux machine - 404 not found error

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-20T03:42:37.4466667+00:00
Praveen Ayyasamy 20 Reputation points
commented 2024-02-20T11:54:43.84+00:00
Praveen Ayyasamy 20 Reputation points
0 answers

Azure Sentinel - Update incident (preview) - ObjectId (over lighthouse) not resolved to source user

Hey, It seems that if you provide either the UPN (with #EXT#)/ or the objectId (that is assigned if you manually assign the incident owner, so it's available) through the logic app block Update Incident (Preview) It does not assign the underlying…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,931 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-15T09:05:03.66+00:00
Wiszowaty, Sebastian 20 Reputation points
commented 2024-02-26T13:44:46.95+00:00
Akshay-MSFT 16,926 Reputation points Microsoft Employee
0 answers

how to have logs sent from multiple different non connected azure and aws tenants to one instance of Azure Sentinel

i have 1 main tenant with our azure arc and azure sentinel instance. i need to get all the machines on several non connected azure and aws tenants to send their logging to our azure sentinel. no vpns are allowed between the tenants. azure arc will work…

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
358 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-13T20:18:00.4+00:00
Darren Phillips 1 Reputation point
commented 2024-02-14T14:59:30.1933333+00:00
Timmy Malmgren 886 Reputation points
0 answers

Azure VM not reporting to LAW | Event Id 4001 Operations Manager

Hi folks, I have an Azure hosted machine which is unable to connect to Azure OMS to export Logs to Azure LAW. However, I am getting connectivity related errors in MMA config manager, Event Id 4001 in Event Logs etc. Though, I have validated the…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,370 questions
Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,433 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-13T19:18:54.5966667+00:00
Apurva Pathak 320 Reputation points
commented 2024-03-07T15:11:09.51+00:00
deherman-MSFT 34,436 Reputation points Microsoft Employee
0 answers

Why I can't see threat intelligence in Sentinel?

I made auto ti indicator using HTTP connector in Logic Apps And, HTTP connector is well, they bring 201 code, success result. enter image description here enter image description here But I can't see result in threatintelligence. enter image description…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-01-19T00:40:13.48+00:00
mara7 161 Reputation points
commented 2024-01-22T20:14:28.3033333+00:00
JamesTran-MSFT 36,496 Reputation points Microsoft Employee
0 answers

How to establish a connection between NSG data connector to Sentinel

I'm facing issue while connecting NSG data connector and Azure Activity data connector to Sentinel. But it is asking for " Policy​: owner role assigned for each policy assignment scope.​" I'm not knowing what role to assign to what…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-01-18T09:47:23.79+00:00
Anirudh K 0 Reputation points
commented 2024-01-18T12:49:00.3833333+00:00
Luis Arias 5,366 Reputation points