MS Sentinel - Data Connectors update

Lutz Rahe 20 Reputation points
2024-06-18T01:44:18.1766667+00:00

Question

MS Sentinel in Azure - Data Conenctors

In Data Conenctors I have 21 onboarded connectos, 17 connected , 0 updates

When I go to "More content at content hub" I can see 17 installed and 3 updates.

QS1: Why these 3 updates are not shown in the Data Connector page?

QS2: These 3 updates are data connectors which are connected. Can I update these connectors without interrupt (e.g. Microsoft Entra ID) or will these updated automatically? (when?)

Best

Lutz

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,051 questions
0 comments No comments
{count} votes

Accepted answer
  1. Akshay-MSFT 17,646 Reputation points Microsoft Employee
    2024-06-21T11:14:55.7+00:00

    @Lutz Rahe

    Thank you for posting your query on Microsoft Q&A, PFB answers inline to your queries:

    • QS1: Why are these 3 updates not shown in the Data Connector page?

    This is because Sentinel Content hub contains the "solution" which provide a consolidated way to acquire Microsoft Sentinel content, like data connectors, workbooks, analytics, and automation, in your workspace with a single deployment step.

    So, the available updates are not just for one data connector but entire solution suit. For example:

    In my content hub I have a solution called "Threat Intelligence" which does show available updates:

    User's image

    But when proceed to manage it, I saw it has 42 configurations of which not all are data connectors**. Which means update for even a single configuration/service would show up as update for entire solution and not just data connector.**

    User's image

    Also for built in solution you must manage updates for out-of-the-box content in the Content hub. Or, for custom content, manage updates from the Repositories page. For more information, see Discover and manage Microsoft Sentinel out-of-the-box content.

    • QS2: These 3 updates are data connectors which are connected. Can I update these connectors without interrupt (e.g. Microsoft Entra ID) or will these updated automatically? (when?)

    Yes, updating content does not have any downtime, however the recommendation is always to have them updated during off business hours to avoid any glitch in updates.

    We could update solutions all at once by hitting update while standalone content updates automatically without any manual task.

    If you don't have any further queries and the suggestion above answers your ask, please "Accept the answer", This will help us and others in the community as well.

    Thanks,

    Akshay Kaushik

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Clive Watson 5,951 Reputation points MVP
    2024-06-18T10:44:49.2466667+00:00

    I have raised the difference in counts a few times with Microsoft, however to answer the question you need to update a connector, they are not force updated. Any change should be planned to avoid peak times.

    0 comments No comments

  2. Lutz Rahe 20 Reputation points
    2024-06-24T00:35:21.25+00:00

    Thank you

    That helps a lot

    Best,

    Lutz

    0 comments No comments