345 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

Custom Data Connector into Sentinel Content-Hub

Hello Microsoft Community, We are planning to build & integrate our custom data connector into the Sentinel Content-Hub to enable data analysis services for our customers who are interested in Azure Sentinel. And our data, which is unique and…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-31T01:00:56.8333333+00:00
LXF 40 Reputation points
accepted 2024-06-03T00:52:36.6733333+00:00
LXF 40 Reputation points
1 answer One of the answers was accepted by the question author.

How Do I Configure JSON Items for Different Types of Data Connectors?

Hello, I'm wondering if there're any wiki pages that give explanation and how to properly configure the data connectors. Thank you! I've been exploring the variety of data connectors available in Azure, such as GenericUI, APIPolling, and others, through…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-30T06:50:41.1533333+00:00
LXF 40 Reputation points
accepted 2024-05-30T23:44:21.3833333+00:00
LXF 40 Reputation points
1 answer One of the answers was accepted by the question author.

The request type when fetching to S3

Hi all, I would like to connect S3 and microsoft sentinel. I have a question. ・I think you fetch files from microsoft sentinel to S3, is the request type GET? The following is the page to which we…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-27T06:40:15.37+00:00
横田 大和 40 Reputation points
accepted 2024-05-30T00:43:17.62+00:00
横田 大和 40 Reputation points
1 answer One of the answers was accepted by the question author.

Moving Sentinel to a different management group

Hey folks, I know that moving Sentinel from one subscription to a different one is not supported and can break things. Could somebody tell me, whether moving a whole subscription that contains a Sentinel instance from one management group to another…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-23T12:30:00.3566667+00:00
Sándor Tőkési 181 Reputation points
accepted 2024-05-29T16:45:31.3066667+00:00
Sándor Tőkési 181 Reputation points
1 answer One of the answers was accepted by the question author.

Threat Intelligence Sharing

Hi all, Is it possible to use threat intelligence from a third party solution with Microsoft sentinel? And if possible, how would you connect them? Custom connectors? regard,

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-23T14:43:59.2633333+00:00
横田 大和 40 Reputation points
accepted 2024-05-27T06:15:28.9033333+00:00
横田 大和 40 Reputation points
1 answer One of the answers was accepted by the question author.

Mismatch in amount of data received in logs analytics workspace and DCR metrics

I have defined a data collection rule and am using logs ingestion api to send data to 2 custom tables. I have defined diagnostic settings for the DCR such that error logs are sent to logs analytics workspace. For about an hour, I have events ingested…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,887 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-03-28T07:47:47.7+00:00
Ashwin Venkatesha 230 Reputation points
commented 2024-05-24T10:08:55.81+00:00
Labcorp 0 Reputation points
1 answer One of the answers was accepted by the question author.

How to get additional details about Mitre attacks like(mitre_tactic_id mitre_technique_id mitre_tactic mitre_technique mitre_subTechnique) ?

Hello, Greetings of the day We are using the below endpoint to collect the alerts. These alerts consist of a wide range of data including mitreTechniques. Further, I would like to know if it is possible to extract more information about Mitre Attacks…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-16T06:05:28.6033333+00:00
Vimalkumar Nayak 20 Reputation points
accepted 2024-05-23T06:31:30.8766667+00:00
Vimalkumar Nayak 20 Reputation points
1 answer One of the answers was accepted by the question author.

Testing Microsoft Defender XDR with Azure Sentinel in a CDX-like Environment

I'm looking to try out Microsoft Defender XDR with Azure Sentinel, but my current setup—a CDX tenant under an E5 subscription—doesn't have an active Azure subscription. Any suggestions for workarounds or similar environments where I can test Microsoft…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-14T06:07:28.7433333+00:00
Avishka Bandarathilaka 20 Reputation points
commented 2024-05-17T10:03:46.94+00:00
Avishka Bandarathilaka 20 Reputation points
1 answer One of the answers was accepted by the question author.

Sentinel Kusto Query todatetime function does not work with dynamic values.

I have a kusto query to calculate MTTR by client. When an incident is resolved, an analyst comments the resolution time in the format R: time where time is when the incident was resolved and R is to make the comment unique. Example R: Friday, May 10,…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-10T11:24:54.8433333+00:00
Julius Ekane 20 Reputation points
accepted 2024-05-14T12:38:04.1866667+00:00
Julius Ekane 20 Reputation points
1 answer One of the answers was accepted by the question author.

Sentinel bicep deployment : InvalidParameter - Solution product cannot start with 'OMSGallery/' as it is reserved for Microsoft first party solutions.

Hello, i am learning how to script and i wish to deploy Sentinel with bicep. I have created a script from Microsoft templates and have added variables as well as a jsonc parameters file. I use VSC with the bicep extension in order to "easily"…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,887 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2023-01-17T16:00:00.0266667+00:00
Dunvael LE ROUX 45 Reputation points
commented 2024-05-14T05:58:23.0133333+00:00
Stanislav Zhelyazkov 21,521 Reputation points MVP
1 answer One of the answers was accepted by the question author.

How are github links created/referenced in function app

I am finding it difficult to understand how are these links generated. https://aka.ms/sentinel-ApigeeXDataConnector-azuredeploy https://aka.ms/sentinel-ApigeeXDataConnector-functionapp I am building a similar function app json for my solution, and I…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-27T00:50:47.2866667+00:00
Ashwin Venkatesha 230 Reputation points
accepted 2024-05-09T04:49:56.79+00:00
Ashwin Venkatesha 230 Reputation points
1 answer One of the answers was accepted by the question author.

Inquiry Regarding Multiple 4624 Event ID Logs for Single User Login

Hello Team, I am reaching out to inquire about a matter related to our Windows Security logs. Specifically, we have observed multiple instances of Event ID 4624 being logged for a single user login event in the Security Events table. As part of our…

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,018 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-01T18:05:09.7033333+00:00
Srisaiteja Palle 20 Reputation points
accepted 2024-05-08T16:56:42.5566667+00:00
Srisaiteja Palle 20 Reputation points
1 answer One of the answers was accepted by the question author.

Respond to incidents across multiple tenants deploying Defender XDR from One Centralized Ms Sentinel

Hello, I have a customer having 3 tenant A,B and C. Tenant A and C each are using Microsoft Defender XDR. MS Sentinel is configured on Tenant B. He want to centralize all events and logs on Sentinel and want to configure responses if any incident is…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-02T13:05:38.2+00:00
Farah MHAMDI 20 Reputation points
commented 2024-05-08T14:54:53.59+00:00
Farah MHAMDI 20 Reputation points
1 answer One of the answers was accepted by the question author.

How to add a function app for azure workbook and sentinel solution

Hi, I am working on contributing to an azure sentinel solution in github, My solution contains data connector and workbooks. Now, I want to add a workbook that talks to a custom endpoint. In this case, the custom endpoint is a function app http…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-30T07:54:16.0666667+00:00
Ashwin Venkatesha 230 Reputation points
accepted 2024-05-07T22:24:11.4133333+00:00
Ashwin Venkatesha 230 Reputation points
1 answer One of the answers was accepted by the question author.

KQL validation is failing locally

I ran dotnet test as per https://github.com/Azure/Azure-Sentinel#run-kql-validation-locally [xUnit.net 00:00:00.41] Exception discovering tests from Kqlvalidations.Tests: System.BadImageFormatException: Could not load file or assembly…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-26T06:17:29.5366667+00:00
Ashwin Venkatesha 230 Reputation points
accepted 2024-05-07T22:01:16.9833333+00:00
Ashwin Venkatesha 230 Reputation points
1 answer One of the answers was accepted by the question author.

Failed to save analytics rule query.

I can create any active analytics rule query in Microsoft Sentinel. While trying to create a new one a error occurs: "Failed to save the analytics rule query. Log Analytics workspace 'xxx' could not be found." It started when the previous…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-05-03T04:18:08.0833333+00:00
3PI 20 Reputation points
accepted 2024-05-07T16:05:25.52+00:00
3PI 20 Reputation points
1 answer One of the answers was accepted by the question author.

Can I create a playbook in Microsoft Sentinel that is able to disable a compromised hybrid user account whose authentication authority is an on-premises Active Directory Domain controller?

I would like to create a playbook that disables a compromised account. The account is synchronised from an on-premises Active Directory Domain Controller. Synchronisation to Microsoft Entra ID is through Microsoft Entra Connect Sync. Password hash…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-27T10:12:42.72+00:00
Anthony K. Simukonda 20 Reputation points
accepted 2024-05-05T09:34:01.37+00:00
Anthony K. Simukonda 20 Reputation points
1 answer One of the answers was accepted by the question author.

30 day challenge for security operations analyst cert module numbers inconsistent

I am doing the 30 day challenge for sc-200 Security Operations Analyst. I have done the 53 modules stated in the challenge, however, my status says 53 of 54 modules completed. I have no info how to get to the 54th module if it exists! URL:…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,000 questions
Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
974 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2024-04-22T15:11:45.55+00:00
Jose Niguidula Enriquez 25 Reputation points
commented 2024-05-03T13:19:58.8166667+00:00
Jose Niguidula Enriquez 25 Reputation points
1 answer One of the answers was accepted by the question author.

Error Whille setting up SMTP Email V3 connection

Hi Team, I am configuring SMTP connection and getting below error Failed to create connection: { "error": { "code": 502, "source": "logic-apis-easteurope.azure-apim.net", "clientRequestId": "",…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2024-04-05T11:33:16.4333333+00:00
Disha Bodade 65 Reputation points
accepted 2024-04-30T05:59:05.1333333+00:00
Disha Bodade 65 Reputation points
1 answer One of the answers was accepted by the question author.

Missing permission 'Microsoft.OperationsManagement/register/action' on scope '/subscriptions/8c507d2e-37ef-4ae1-864f-fd05f45b3cdb' is required to add Microsoft Sentinel to the selected workspace

Hi I'm facing problem when I tried to subscribe to Microsoft Sentinel. When I tried to add Microsoft Sentinel to my desire workspace , this notification pops up. I do have the Owner and Security Administrator permission. Can someone please enlighten me…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,006 questions
asked 2023-03-16T09:02:09.1466667+00:00
Muhammad Zariq Razali 20 Reputation points
commented 2024-04-29T15:31:47.4366667+00:00
John Munro 0 Reputation points