135 questions with Microsoft Sentinel tags

Sort by: Updated
0 answers

Syslog Transformation DCR not working

I need assistance troubleshooting a Syslog Transformation DCR used with Microsoft Sentinel. The Transformation DCR looks to work correctly in the Create Transformation wizard, but doesn't actually filter out the records. I have a few Syslog/CEF…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,922 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-29T16:03:21.6833333+00:00
Greg Sneed 0 Reputation points
commented 2024-06-14T10:23:33.5133333+00:00
AnuragSingh-MSFT 20,986 Reputation points
0 answers

Syslog through AMA (CEF) Connector

Hi, Follwing up on my last question: https://learn.microsoft.com/en-us/answers/questions/1690671/syslog-through-ama-connector-not-showing-in-the-co I have now installed Arc, and the machine is showing up on Azure Arc. The AMA is installed and is…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,922 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-11T10:30:54.9766667+00:00
Bl()e 5 Reputation points
commented 2024-06-14T10:14:19.01+00:00
Graham Bloice 0 Reputation points
0 answers

API Version Discrepancies for 'Data Connector Definitions' in Sentinel

Hello MS Community, Would you please help explain the discrepancy regarding API references to "data connector definitions"? I noticed the API related link…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-14T08:30:15.17+00:00
LXF 120 Reputation points
0 answers

DataConnector connectorUI attributes - sampleQueries

hey folks, I was working on some data connectors and seemingly some of the old features are not working anymore. I tried to use some fields which seem to be dated now. The most relevant would be the 'sampleQueries' attribute. I remember having these in…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-10T08:25:05.6566667+00:00
Sándor Tőkési 181 Reputation points
commented 2024-06-11T14:53:19.3366667+00:00
Sándor Tőkési 181 Reputation points
0 answers

how Azure ARM templates process placeholders please?

Could you explain how Azure ARM templates process placeholders and variables during deployment, especially comparing the '[variables]' syntax with templating mechanisms like {{variables}}? I see some of the codes (from Sentinel Solution folder @ github)…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-11T02:47:43.6333333+00:00
LXF 120 Reputation points
commented 2024-06-11T10:06:35.52+00:00
Akshay-MSFT 16,931 Reputation points Microsoft Employee
0 answers

logo size for Sentinel Content Preparation

Hello, I am preparing the Sentinel content according to the following steps from github, my question is if there's requirement about the size of the logo? Thanks.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-06-03T09:35:57.3066667+00:00
LXF 120 Reputation points
commented 2024-06-03T19:11:38.1266667+00:00
Marilee Turscak-MSFT 35,616 Reputation points Microsoft Employee
0 answers

Sentinel - Sophos Endpoint Protection (using REST API) (Preview) - Fails due to trying to create a table with a hyphen!

When trying to configure and deploy the new Sophos API connector for Sentinel it fails. Looks like it's trying to create a new table called Custom-SophosEPAlerts_CL but tables cannot contain hyphens so needs changing to CustomSophosEPAlerts_CL…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-22T09:34:28.36+00:00
James Grant 0 Reputation points
commented 2024-05-28T12:43:58.3066667+00:00
Andrew Blumhardt 9,676 Reputation points Microsoft Employee
0 answers

Extensions AMA - Impossible to install agent

Hello, I'm trying to deploy an AMA extension but I m stuck in "creating" with the following error messages from the Guestconfig file on a RHEL 9 linux servers: [2024-05-15 15:52:30.135] [PID 1117] [TID 1629] [Pull Client] [INFO] Successfully…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-05-15T14:42:38.4966667+00:00
Christophe Rosenkranz 5 Reputation points
edited the question 2024-05-16T19:09:30.2466667+00:00
Christophe Rosenkranz 5 Reputation points
0 answers

Tenable Io sentinel solution can not identify log analytics work space?

Tenable Io sentinel solution can not identify log analytics work space?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2022-07-31T07:15:47.387+00:00
Sherif Israil Saad 1 Reputation point
commented 2024-05-11T03:06:52.74+00:00
Sherif Israil Saad 1 Reputation point
0 answers

Remove a mobile device from a user

Anyone has built a sentinel playbook / logic app to be able to remove active sync device from a user? And could share some details on how this was done?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,094 questions
asked 2023-07-02T21:27:54.2933333+00:00
Someread87 0 Reputation points
commented 2024-04-16T10:05:59.3566667+00:00
Fiona Matu 86 Reputation points Microsoft Employee
0 answers

Query set to run in my Logic App is timing out and failing

Hello everyone. I am trouble shooting an issue with my Logic App in which after an incident triggers, the next step is to run the query and list the results, but this part of the Logic App is what is timing out and failing. When reading the timeout…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,933 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-21T13:17:52.54+00:00
Matthew Agosta 0 Reputation points
edited a comment 2024-04-03T09:27:33.3133333+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Microsoft Defender for Office 365 (0/5 connected)​ : In Defender XDR connector, Office 365 logs cannot be connected in Sentinel.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-19T15:18:44.7266667+00:00
Mohammad Sayeem Chowdhury 0 Reputation points
commented 2024-03-20T09:10:54.34+00:00
Givary-MSFT 29,351 Reputation points Microsoft Employee
0 answers

Cannot view Sentinel alert for some incidents but the alert can be found in Defender for Endpoint portal using Graph

I have enabled automatic incident creation for Defender for Endpoint in Sentinel but when I try to view some alerts associated with the created incidents, nothing is displayed. Despite this, I can locate the relevant alert in the Security (Defender for…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,051 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-12T07:17:33.5466667+00:00
Spyros Ermogenous 0 Reputation points
commented 2024-03-15T12:24:32.9766667+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Getting Error while saving Analytics rule as "the provided 'productFilter' was not recognized as a valid product"

Team, I am trying to Create Analytics Rule, Also created a Automation Rule with default options and created one playbook to run n action of that automation rule. But while Saving the Analytics Rule, Sentinel through below error. Failed to save analytics…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-03-11T12:43:30.48+00:00
Disha Bodade 65 Reputation points
commented 2024-03-12T10:42:29.35+00:00
Akshay-MSFT 16,931 Reputation points Microsoft Employee
0 answers

CloudWatch ASIM Parser

I have successfully connected AWS CloudWatch to Sentinel, and I am receiving events from multiple log groups. However, I am facing an issue with parsing the events, particularly with the 'Message' field that is in JSON format. Currently, the 'Message'…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-01-16T09:26:19.8533333+00:00
LS 15 Reputation points
commented 2024-03-11T10:55:27.48+00:00
Monika Sharma 0 Reputation points
0 answers

Azure VM not reporting to LAW | Event Id 4001 Operations Manager

Hi folks, I have an Azure hosted machine which is unable to connect to Azure OMS to export Logs to Azure LAW. However, I am getting connectivity related errors in MMA config manager, Event Id 4001 in Event Logs etc. Though, I have validated the…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,372 questions
Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,433 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-13T19:18:54.5966667+00:00
Apurva Pathak 320 Reputation points
commented 2024-03-07T15:11:09.51+00:00
deherman-MSFT 34,436 Reputation points Microsoft Employee
0 answers

Playbook ARM template generator broken

Hey, I have been using the playbook ARM template generator for years and the past week it does not work at all. It tries to log into local host to present the portal but it does not work correctly. I have tried it on 3 machines and several browsers. …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-24T08:56:37.66+00:00
Cloudsec 150 Reputation points
commented 2024-03-06T03:13:17.03+00:00
Andrew Blumhardt 9,676 Reputation points Microsoft Employee
0 answers

Sentinel widgets and private endpoint

Do the widgets and Insights works Incidents panel in Sentinel when the Log Analytics Workspace uses private endpoints? "externaldata operator"…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-28T15:28:28.55+00:00
Peter Fischer 1 Reputation point
commented 2024-02-28T18:10:15.7966667+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Error data connector Github audit logs

Hi everyone. I am trying to make the connection between github and sentinel. I am trying to have the GitHub Enterprise Audit Log connector up, but somehow when I put the name of the Organization and the API key I got an error " Forbidden -…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2023-03-30T10:05:44.5066667+00:00
Bogdan Stoica 10 Reputation points
commented 2024-02-26T22:15:24.37+00:00
Fiona Matu 86 Reputation points Microsoft Employee
0 answers

Azure Sentinel - Update incident (preview) - ObjectId (over lighthouse) not resolved to source user

Hey, It seems that if you provide either the UPN (with #EXT#)/ or the objectId (that is assigned if you manually assign the incident owner, so it's available) through the logic app block Update Incident (Preview) It does not assign the underlying…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,933 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,019 questions
asked 2024-02-15T09:05:03.66+00:00
Wiszowaty, Sebastian 20 Reputation points
commented 2024-02-26T13:44:46.95+00:00
Akshay-MSFT 16,931 Reputation points Microsoft Employee