1,056 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer

Microsoft Sentinel - Add note to table or function in KQL

Hello I was wondering if there is a way to attach a note to a specific table or function in KQL so that an analyst using the table will see it when they use it in a query? I work for an MSSP providing managed Sentinel SIEM. Analyst will regularly create…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-17T11:55:15.95+00:00
jake stewart 0 Reputation points
answered 2024-07-18T16:26:16.8466667+00:00
Clive Watson 5,951 Reputation points MVP
0 answers

Monitor Sentinel environment.

We are entering into an arrangement with a vendor who is supposed to monitor our Sentinel environment for us. They wanted to use Azure Lighthouse to enable access to our tenant, but we want to do this in the least privileged way - we only want to give…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-18T13:56:20.4733333+00:00
Schifter, Gabriela 160 Reputation points
0 answers

How to ingest NetFlow into Sentinel

Is there a Sentinel connector for Cisco NetFlow ?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-18T13:32:34.2833333+00:00
Chad Hutchings 0 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How do i troubleshoot after PR's issued?

Hello, We have submitted a pull request to GitHub for our Sentinel Solution. I noticed that the pipeline checks, as shown below, include some unresolved issues that are confusing to us. Could you please let us know who we should contact to resolve these…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-18T04:19:34.97+00:00
LXF 180 Reputation points
edited the question 2024-07-18T07:32:52.8066667+00:00
Givary-MSFT 30,596 Reputation points Microsoft Employee
0 answers

Microsoft Sentinel Solution for Microsoft Power Platform

I’ve been testing the Microsoft Sentinel Solution for the Power Platform, and I’m encountering an issue with the Power Platform inventory data connector. This connector uses a Azure Function App to ingest inventory and usage data from an Azure Data Lake…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
Microsoft Power Platform Training
Microsoft Power Platform Training
Microsoft Power Platform: An integrated set of Microsoft business intelligence services.Training: Instruction to develop new skills.
210 questions
asked 2024-07-17T17:32:46.93+00:00
Gord B 0 Reputation points
edited the question 2024-07-17T17:45:22.4266667+00:00
Gord B 0 Reputation points
1 answer

Is there a way to Query all Table Schemas to count How many Columns every Table in Sentinel has using KQL

I am Trying to return a list of tables where they have more than a certain amount of columns, get schema works but it would be a painful task to run it for every table. The Table name is also not maintained when you run getSchema so I tried to union all…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-16T11:52:21.9533333+00:00
Andrew Ryan 0 Reputation points
commented 2024-07-17T10:19:32.63+00:00
Andrew Ryan 0 Reputation points
0 answers

Azure virtual desktop session alerts triggered by hostname changes

Our Azure virtual desktop keeps raising "pass the ticket" attack alerts when the hostname of our computers changes from <hostname> to <hostname>-<random number>. However, our security logs remain the same inside the SIEM,…

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,447 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-16T04:55:47.8+00:00
Heath Smart Dylan 0 Reputation points
commented 2024-07-17T07:16:51.0433333+00:00
Prrudram-MSFT 22,976 Reputation points
0 answers

Scaling your CICD pipeline - Default parameter file is not being used

I am currently working on a CICD pipeline in combination with MS Sentinel content. I just got in touch with the repository and the process of handling parameter files. I am just asking myself why the default parameter file is not being used. All of my…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-16T09:17:24.5566667+00:00
Wagner Nico 0 Reputation points
commented 2024-07-16T14:56:08.82+00:00
Givary-MSFT 30,596 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

How to execute microsoft sentinel's backups and recovery

Hi, I'm starting in Microsoft Sentinel and read a lot of documents but I couldn't find anything about backup and recovery. Anybody know something about this? Please give some advices Thank you in advance Best regards,

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2022-03-02T19:58:55.197+00:00
Nelba Sanchez 21 Reputation points
commented 2024-07-16T11:38:38.1433333+00:00
Ngo, Thanh 0 Reputation points
0 answers

Sentinel to azure firewall connection issues

I am having issues connecting sentinel to azure firewall. I have establish 9 other connections no problem but not to the azure firewall from sentinel data connector. I have rebuilt the firewall several times, I confirmed the diagnostic log setting and…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-09T18:44:56.13+00:00
Sapphire BLU 0 Reputation points
commented 2024-07-15T07:27:30.0733333+00:00
Givary-MSFT 30,596 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How to retrieve output data after the deployment

Hello there, I am wondering if there's a straightforward method to retrieve the output results after a deployment is completed. By 'straightforward,' I mean configuring a specific API-link during the deployment to which the output data, along with its…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-09T02:00:48.7+00:00
LXF 180 Reputation points
accepted 2024-07-15T05:58:10.1766667+00:00
LXF 180 Reputation points
3 answers

Export Logs from Log Analytics Workspace to Blob Storage

Hi all, I have a Log Analytics Workspace that is linked to Sentinel. I have a lot of logs that I need to export from the Workspace into Blob Storage. Th logs date back 30 days and it is about 400GB, it is about 500 million logs. Please let me know what…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,612 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-11T12:37:19.9733333+00:00
Adriaan Boshoff 0 Reputation points
commented 2024-07-12T10:40:36.3+00:00
Adriaan Boshoff 0 Reputation points
2 answers One of the answers was accepted by the question author.

Azure Sentinel Log Screen KQL mode to start by default

Azure Sentinel changed about a month ago the Log page GUI. It added a default Simple Mode, which does not seem to allow to enter KQL query by typing. The KQL mode, much more practical, needs to be selected over and over in the right side of the screen.…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-10T11:05:41.85+00:00
Jan Stodola 56 Reputation points
commented 2024-07-11T21:03:24.02+00:00
Jan Stodola 56 Reputation points
0 answers

Sentinel _BilledSize and estimate_data_size differences

hey folks Could somebody tell me the relationship between the _BilledSize field in a log and the result of the estimate_data_size(*) KQL command? I do understand that the _BilledSize field contains the info of the size of the data I have to pay for…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-07T14:02:15.47+00:00
Sándor Tőkési 181 Reputation points
commented 2024-07-11T09:16:11.9366667+00:00
Sándor Tőkési 181 Reputation points
1 answer

ActionConditionFailed The execution of template action 'Get_user' is skipped: there are no items to repeat.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-03T20:49:14.5+00:00
A Amir Shaltami 0 Reputation points
edited the question 2024-07-11T07:14:02.17+00:00
VarunTha 5,735 Reputation points Microsoft Vendor
1 answer

Can not enable MSD Threat Intelligence Data Connector

I have a cx that is getting the error below when attempting to enable Microsoft Defender Threat Intelligence data connector. He is using the (Preview) version. What could be causing this?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-09T23:56:42.1833333+00:00
DG001 386 Reputation points Microsoft Employee
answered 2024-07-11T06:49:15.7833333+00:00
Givary-MSFT 30,596 Reputation points Microsoft Employee
1 answer

Segregating and Identifying Alerts in Sentinel Workspace

I am seeking a method to segregate alerts in a Sentinel workspace to facilitate easier identification and prioritization. For instance, if we have multiple clients' logs in a single workspace, we need a way to identify and segregate alerts based on the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-07-03T04:32:08.67+00:00
Someiah C S 80 Reputation points
commented 2024-07-11T04:12:27.13+00:00
Givary-MSFT 30,596 Reputation points Microsoft Employee
1 answer

Sentniel free data sources

Hi, quoting from https://learn.microsoft.com/en-us/azure/sentinel/billing?tabs=commitment-tier#free-data-sources "The following data sources are free with Microsoft Sentinel: Azure Activity Logs. Office 365 Audit Logs, including all…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2022-09-13T13:01:19.587+00:00
AdamBudziski-8216 16 Reputation points
commented 2024-07-10T05:16:14.0833333+00:00
EnterpriseArchitect 5,116 Reputation points
0 answers

CloudWatch ASIM Parser

I have successfully connected AWS CloudWatch to Sentinel, and I am receiving events from multiple log groups. However, I am facing an issue with parsing the events, particularly with the 'Message' field that is in JSON format. Currently, the 'Message'…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2024-01-16T09:26:19.8533333+00:00
LS 20 Reputation points
commented 2024-07-09T22:21:18.2633333+00:00
Brian Bye 0 Reputation points
1 answer

Sentinel as IaC with Terraform

Hi, Trying to instantiate Sentinel using Terraform. Should be straightforward, create a resource group (azurerm_resource_group), log analytics workspace (azurerm_log_analytics_workspace), onboarding Sentinel…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,056 questions
asked 2023-08-23T05:55:02.6333333+00:00
AdamBudzinskiAZA-0329 91 Reputation points
answered 2024-07-09T12:49:59.4766667+00:00
Eduardo Perez 0 Reputation points