How to disconnect Azure Sentinel data connectors?
In Sentinel I cant able to find an option to disconnect the data connectors . And there are no documents available for the same. So what are the methods to disconnect a data connector inside sentinel for both native and non native products. When I…
Required document for starting the procurement
we decided to purchase sentinel and for starting the procurement i need the following documents what should i do: Terms and Conditions Data Processing Agreement (DPA) Privacy Policy ISO 27001 and SOC 2 certifications I need the necessary documents to…
Microsoft Defender Threat Intelligence honeypot
Hi, I've added the Microsoft Defender Threat Intelligence Data Connector to Sentinel and I get thousands of honeypot alerts in the Threat Intelligence page, how can I filter these notifications?
how can I validate my Sentinel Content before PR ?
Hello MS Team, I am currently engaged in validating/testing solutions (a CCP dataConnector) with Sentinel and have a few questions regarding the process. Q1: I am following the Sentinel-DataConnector readme guidance…
About "u.dataTypes is undefined" when importing DataConnector json
Hello, I encountered an error "u.dataTypes is undefined" when importing a CPP on Sentinel. I am pretty sure that the table name is correct within my current workspace. Can some one explain this error please? Thanks in advance.
Trying to add Microsoft Sentinel to a Log Analytics Workspace in Azure but keep getting error "The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time period"
I am trying to add Microsoft Sentinel to a Log Analytics Workspace connected to a Virtual Machine in the Azure portal but keep getting the error "The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time…
Whenever I try to create microsoft sentinel it shows error
Failed to add Microsoft Sentinel Failed to add Microsoft Sentinel to workspace 'SentinelRG'. The gateway did not receive a response from 'Microsoft.SecurityInsights' within the specified time period.
Stop Creating Incidents in Sentinel For every Alert generated by Custom detection rule in defender for endpoint
Hi Team, I have created a custom rule in Defender with KQL query to get the details about Device & owners of Vulnerable machines. So results are having rows more than 1500, and its generating that many alerts in defender. And same events are getting…
![](https://techprofile.blob.core.windows.net/images/7EQ5-HY98kGi4i9V9wyPSg.png?8DAAFF)
Syslog Transformation DCR not working
I need assistance troubleshooting a Syslog Transformation DCR used with Microsoft Sentinel. The Transformation DCR looks to work correctly in the Create Transformation wizard, but doesn't actually filter out the records. I have a few Syslog/CEF…
DataConnector connectorUI attributes - sampleQueries
hey folks, I was working on some data connectors and seemingly some of the old features are not working anymore. I tried to use some fields which seem to be dated now. The most relevant would be the 'sampleQueries' attribute. I remember having these in…
Azure Activity Data connector configuration
Hi, I am trying to configure the Azure Activity data connector in my tenant. I have installed the connector and configured the azure policy scoped at my subscription where i have sentinel deployed. In the parameter section I have set my sentinel…
Syslog through AMA (CEF) Connector
Hi, Follwing up on my last question: https://learn.microsoft.com/en-us/answers/questions/1690671/syslog-through-ama-connector-not-showing-in-the-co I have now installed Arc, and the machine is showing up on Azure Arc. The AMA is installed and is…
how to Deploy Sysmon To Receive Logs In Azure Sentinel?
how to Deploy Sysmon To Receive Logs In Azure Sentinel?
Deploy estreamer connector using load balancer
Hi all, I wanted to deploy solution like this. An azure vm, azure sentinel, azure load balancer and Cisco estreamer connector How do I configure the estreamer to point directly to azure load balancer instead of azure vm agent
Find creation date of custom analytical rule created in Sentinel
Hi all, I am aiming to find the number of new analytical rules created per month (including custom as well as from github deployed), as well as the existing total per month on Sentinel for the last 2 months and present it to a Sentinel workbook. How…
![](https://techprofile.blob.core.windows.net/images/O_6JxFykNkWAyX0qE9x4-A.png?8DC91F)
![](https://techprofile.blob.core.windows.net/images/7EQ5-HY98kGi4i9V9wyPSg.png?8DAAFF)
How to write a kql comparing 2 different tables(signins, threatintelligence) to create alert if the sign in ip matches with the ip reported by threatintelligence.
I tried multiple ways to join the tables but ended up getting multiple errors, and I am not able to call the table that I referred into a variable using the let operator after I refer other table after it. As I was not able to use the first defined…
MS Sentinel - Data Connectors update
Question MS Sentinel in Azure - Data Conenctors In Data Conenctors I have 21 onboarded connectos, 17 connected , 0 updates When I go to "More content at content hub" I can see 17 installed and 3 updates. QS1: Why these 3 updates are not shown…
Automated email sending when running a KQL query
Hello, First of all, I'm quite new in Sentinel/KQL related stuff. I have this very basic KQL query to find sign-ins from countries not included in the "LocationDetails" argument. I'd like to automate this query and, if any results found, send…
AMA+DCR for Syslog & CEF logs. CEF logs in CommonSecurityLog not parsing .
Referring to this article: https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog I trying to solution the following scenario: Using a single Linux log collector to forward both Syslog and CEF events to your Microsoft Sentinel workspaces…
Shannon Entropy evaluation for domains?
Hi, I've found the Entropy calculation for processes running on a device and I've noticed the previously posted questions similar to what I'm asking a few years ago but couldn't find a definitive answer. Just wondering if there is a way of calculating…