1,037 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer

How to disconnect Azure Sentinel data connectors?

In Sentinel I cant able to find an option to disconnect the data connectors . And there are no documents available for the same. So what are the methods to disconnect a data connector inside sentinel for both native and non native products. When I…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-28T16:23:07.86+00:00
RAHUL MP 0 Reputation points
answered 2024-06-28T16:47:10.6666667+00:00
Marcin Policht 16,420 Reputation points MVP
1 answer One of the answers was accepted by the question author.

Required document for starting the procurement

we decided to purchase sentinel and for starting the procurement i need the following documents what should i do: Terms and Conditions Data Processing Agreement (DPA) Privacy Policy ISO 27001 and SOC 2 certifications I need the necessary documents to…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-27T09:19:49.7066667+00:00
Ali Salempanah 20 Reputation points
accepted 2024-06-28T08:43:11.59+00:00
Ali Salempanah 20 Reputation points
2 answers One of the answers was accepted by the question author.

Microsoft Defender Threat Intelligence honeypot

Hi, I've added the Microsoft Defender Threat Intelligence Data Connector to Sentinel and I get thousands of honeypot alerts in the Threat Intelligence page, how can I filter these notifications?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-23T14:29:55.2966667+00:00
Romar 106 Reputation points
commented 2024-06-28T05:43:05.37+00:00
Romar 106 Reputation points
1 answer One of the answers was accepted by the question author.

how can I validate my Sentinel Content before PR ?

Hello MS Team, I am currently engaged in validating/testing solutions (a CCP dataConnector) with Sentinel and have a few questions regarding the process. Q1: I am following the Sentinel-DataConnector readme guidance…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-27T01:39:27.0266667+00:00
LXF 160 Reputation points
accepted 2024-06-28T01:06:53.0566667+00:00
LXF 160 Reputation points
2 answers One of the answers was accepted by the question author.

About "u.dataTypes is undefined" when importing DataConnector json

Hello, I encountered an error "u.dataTypes is undefined" when importing a CPP on Sentinel. I am pretty sure that the table name is correct within my current workspace. Can some one explain this error please? Thanks in advance.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-26T07:01:40.3166667+00:00
LXF 160 Reputation points
accepted 2024-06-28T01:04:56.9433333+00:00
LXF 160 Reputation points
0 answers

Trying to add Microsoft Sentinel to a Log Analytics Workspace in Azure but keep getting error "The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time period"

I am trying to add Microsoft Sentinel to a Log Analytics Workspace connected to a Virtual Machine in the Azure portal but keep getting the error "The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
PowerShell
PowerShell
A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
2,256 questions
asked 2024-06-27T04:27:49.0766667+00:00
Aaqib Ali 0 Reputation points
edited the question 2024-06-27T20:34:57.63+00:00
Aaqib Ali 0 Reputation points
1 answer

Whenever I try to create microsoft sentinel it shows error

Failed to add Microsoft Sentinel Failed to add Microsoft Sentinel to workspace 'SentinelRG'. The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time period.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-27T05:17:35.7+00:00
Zawar Khan 0 Reputation points
answered 2024-06-27T09:07:33.15+00:00
Givary-MSFT 30,071 Reputation points Microsoft Employee
1 answer

Stop Creating Incidents in Sentinel For every Alert generated by Custom detection rule in defender for endpoint

Hi Team, I have created a custom rule in Defender with KQL query to get the details about Device & owners of Vulnerable machines. So results are having rows more than 1500, and its generating that many alerts in defender. And same events are getting…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-25T17:06:28.82+00:00
Disha Bodade 65 Reputation points
answered 2024-06-27T07:37:46.9866667+00:00
Akshay-MSFT 17,486 Reputation points Microsoft Employee
1 answer

Syslog Transformation DCR not working

I need assistance troubleshooting a Syslog Transformation DCR used with Microsoft Sentinel. The Transformation DCR looks to work correctly in the Create Transformation wizard, but doesn't actually filter out the records. I have a few Syslog/CEF…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,957 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-05-29T16:03:21.6833333+00:00
Greg Sneed 0 Reputation points
commented 2024-06-27T04:11:05.89+00:00
AnuragSingh-MSFT 21,076 Reputation points
1 answer

DataConnector connectorUI attributes - sampleQueries

hey folks, I was working on some data connectors and seemingly some of the old features are not working anymore. I tried to use some fields which seem to be dated now. The most relevant would be the 'sampleQueries' attribute. I remember having these in…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-10T08:25:05.6566667+00:00
Sándor Tőkési 181 Reputation points
commented 2024-06-26T18:04:38.8733333+00:00
Sándor Tőkési 181 Reputation points
2 answers One of the answers was accepted by the question author.

Azure Activity Data connector configuration

Hi, I am trying to configure the Azure Activity data connector in my tenant. I have installed the connector and configured the azure policy scoped at my subscription where i have sentinel deployed. In the parameter section I have set my sentinel…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-24T07:30:46.6266667+00:00
Herman 20 Reputation points
commented 2024-06-26T07:33:10.7433333+00:00
Herman 20 Reputation points
0 answers

Syslog through AMA (CEF) Connector

Hi, Follwing up on my last question: https://learn.microsoft.com/en-us/answers/questions/1690671/syslog-through-ama-connector-not-showing-in-the-co I have now installed Arc, and the machine is showing up on Azure Arc. The AMA is installed and is…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,957 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-11T10:30:54.9766667+00:00
Bl()e 25 Reputation points
edited a comment 2024-06-25T18:06:41.0866667+00:00
Dmitry Nikolaenya 0 Reputation points
1 answer One of the answers was accepted by the question author.

how to Deploy Sysmon To Receive Logs In Azure Sentinel?

how to Deploy Sysmon To Receive Logs In Azure Sentinel?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2022-01-05T05:28:24.213+00:00
Shital Khatri - AzureAdmin 101 Reputation points
commented 2024-06-25T12:39:46.2033333+00:00
useR 0 Reputation points
0 answers

Deploy estreamer connector using load balancer

Hi all, I wanted to deploy solution like this. An azure vm, azure sentinel, azure load balancer and Cisco estreamer connector How do I configure the estreamer to point directly to azure load balancer instead of azure vm agent

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-24T03:53:18.3733333+00:00
TAH 0 Reputation points
commented 2024-06-25T07:46:48.5933333+00:00
Givary-MSFT 30,071 Reputation points Microsoft Employee
1 answer

Find creation date of custom analytical rule created in Sentinel

Hi all, I am aiming to find the number of new analytical rules created per month (including custom as well as from github deployed), as well as the existing total per month on Sentinel for the last 2 months and present it to a Sentinel workbook. How…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-21T13:16:42.7966667+00:00
Ev s 0 Reputation points
answered 2024-06-24T18:15:37.6466667+00:00
Akshay-MSFT 17,486 Reputation points Microsoft Employee
0 answers

How to write a kql comparing 2 different tables(signins, threatintelligence) to create alert if the sign in ip matches with the ip reported by threatintelligence.

I tried multiple ways to join the tables but ended up getting multiple errors, and I am not able to call the table that I referred into a variable using the let operator after I refer other table after it. As I was not able to use the first defined…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-23T20:18:15.57+00:00
Harish Menti 0 Reputation points
commented 2024-06-24T05:11:58.0033333+00:00
Givary-MSFT 30,071 Reputation points Microsoft Employee
3 answers One of the answers was accepted by the question author.

MS Sentinel - Data Connectors update

Question MS Sentinel in Azure - Data Conenctors In Data Conenctors I have 21 onboarded connectos, 17 connected , 0 updates When I go to "More content at content hub" I can see 17 installed and 3 updates. QS1: Why these 3 updates are not shown…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-18T01:44:18.1766667+00:00
Lutz Rahe 20 Reputation points
accepted 2024-06-24T00:42:51.4966667+00:00
Lutz Rahe 20 Reputation points
1 answer One of the answers was accepted by the question author.

Automated email sending when running a KQL query

Hello, First of all, I'm quite new in Sentinel/KQL related stuff. I have this very basic KQL query to find sign-ins from countries not included in the "LocationDetails" argument. I'd like to automate this query and, if any results found, send…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-03-04T13:22:29.6466667+00:00
Josep Marzo 20 Reputation points
edited a comment 2024-06-22T22:00:02.59+00:00
Cory Vickstrom 0 Reputation points
3 answers One of the answers was accepted by the question author.

AMA+DCR for Syslog & CEF logs. CEF logs in CommonSecurityLog not parsing .

Referring to this article: https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog I trying to solution the following scenario: Using a single Linux log collector to forward both Syslog and CEF events to your Microsoft Sentinel workspaces…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2023-09-08T07:11:58.8+00:00
Hann, Yap Sheu 20 Reputation points
answered 2024-06-21T23:50:24.67+00:00
Perry Thompson 0 Reputation points
1 answer

Shannon Entropy evaluation for domains?

Hi, I've found the Entropy calculation for processes running on a device and I've noticed the previously posted questions similar to what I'm asking a few years ago but couldn't find a definitive answer. Just wondering if there is a way of calculating…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,037 questions
asked 2024-06-20T08:10:55.9133333+00:00
Holmes, Sam 5 Reputation points
answered 2024-06-21T21:45:10.7766667+00:00
Marilee Turscak-MSFT 35,901 Reputation points Microsoft Employee