1,042 questions with Microsoft Sentinel tags

Sort by: Updated
3 answers One of the answers was accepted by the question author.

AMA+DCR for Syslog & CEF logs. CEF logs in CommonSecurityLog not parsing .

Referring to this article: https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog I trying to solution the following scenario: Using a single Linux log collector to forward both Syslog and CEF events to your Microsoft Sentinel workspaces…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2023-09-08T07:11:58.8+00:00
Hann, Yap Sheu 20 Reputation points
answered 2024-06-21T23:50:24.67+00:00
Perry Thompson 0 Reputation points
1 answer

Shannon Entropy evaluation for domains?

Hi, I've found the Entropy calculation for processes running on a device and I've noticed the previously posted questions similar to what I'm asking a few years ago but couldn't find a definitive answer. Just wondering if there is a way of calculating…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-20T08:10:55.9133333+00:00
Holmes, Sam 5 Reputation points
answered 2024-06-21T21:45:10.7766667+00:00
Marilee Turscak-MSFT 36,156 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How to agentlessly upload logs to a default table in a log analytics workspace?

I have built a system that creates a log analytics workspace and uploads logs to a custom table by following these Microsoft tutorials: https://learn.microsoft.com/en-us/azure/azure-monitor/logs/tutorial-logs-ingestion-api?tabs=dcr …

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,973 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
1,059 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-19T11:49:57.39+00:00
42726446 40 Reputation points
accepted 2024-06-20T10:12:35.3+00:00
42726446 40 Reputation points
1 answer

Set total retention period for one or more tables

Hi, I am trying to set the total retention time for one or more log tables using the command az monitor log-analytics workspace table update --subscription <subscription id> --resource-group sentinel --workspace-name <name> --name…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-18T18:39:12.59+00:00
Nikhil Padma 0 Reputation points
commented 2024-06-19T00:42:28.02+00:00
Nikhil Padma 0 Reputation points
2 answers

Syslog through AMA connector not showing in the content hub list.

Hi, Trying to set up a syslog ingestion into Sentinel for testing. The setup consists of AMA on a on-prem syslog server. The legacy agent is soon not supported, and the requirement of AMA on-prem is according to Microsoft guides to have the following…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-03T09:40:15.5033333+00:00
Bl()e 25 Reputation points
edited a comment 2024-06-18T12:34:48.98+00:00
Andrew Blumhardt 9,831 Reputation points Microsoft Employee
0 answers

Azure Monitor Agent Fluent Bit CVE-2024-4323.

Hello, two questions about Azure Monitor Agent Fluent Bit exe in regards to CVE-2024-4323. AMA agent installation is using fluent-bit.exe in version 2.0.9 (location C:\Program Files\Azure Monitor Agent\Monitoring\Agent\fluent-bit.exe) I would like…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,973 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-17T09:51:44.58+00:00
B T 0 Reputation points
edited the question 2024-06-18T03:55:38.18+00:00
PRADEEPCHEEKATLA-MSFT 84,771 Reputation points Microsoft Employee
1 answer

I and others in my organization are members of "Microsoft Sentinel Contributor" but sometimes we cannot close Sentinel Incidents

I and others in my organization are members of "Microsoft Sentinel Contributor" We can usually close the incidents but sometimes we cannot close them. I have verified my role assignments and since I have the role of "Microsoft Sentinel…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-05T18:54:35.8733333+00:00
JCrockett 0 Reputation points
commented 2024-06-17T15:53:46.1266667+00:00
JCrockett 0 Reputation points
1 answer One of the answers was accepted by the question author.

Migrating Sentinel DNS event connector from legacy agent to AMA

Hi I am in the process of migrating the Sentinel Windows security and DNS data connectors from the legacy agent to AMA. We use the DNS audit log 519 events to resolve device names from ip addresses where the device name is not returned in a lookup query.…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-05T10:08:43.27+00:00
Louise Atyeo 25 Reputation points
accepted 2024-06-17T13:04:29.7+00:00
Louise Atyeo 25 Reputation points
3 answers

How to audit the creator of an Enterprise Application in Azure

Hy I'm trying to get the creator of an "Enterprise Application", as soon as someone is creating one by query below. AuditLogs | where Category =~ "ApplicationManagement" | where OperationName =~ "Add application" | mv-expand…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,398 questions
asked 2024-02-07T16:11:00.8033333+00:00
Stalder Jonas 0 Reputation points
commented 2024-06-12T19:26:17.6533333+00:00
Olivier López Chaverri 0 Reputation points
1 answer One of the answers was accepted by the question author.

Custom detection rule

We see that 90% of the SPAM geared toward students comes from fake Gmail accounts. In Advanced Hunting I created a KQL query to find any Gmail account that sent more than 40 emails from the same account I saved it as a Custom Detection Rule. …

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
27 questions
asked 2024-06-07T21:32:24.7433333+00:00
Runge, Larry 20 Reputation points
commented 2024-06-12T13:42:53.4233333+00:00
Runge, Larry 20 Reputation points
1 answer

how Azure ARM templates process placeholders please?

Could you explain how Azure ARM templates process placeholders and variables during deployment, especially comparing the '[variables]' syntax with templating mechanisms like {{variables}}? I see some of the codes (from Sentinel Solution folder @ github)…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
Azure Startups
Azure Startups
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.Startups: Companies that are in their initial stages of business and typically developing a business model and seeking financing.
236 questions
asked 2024-06-11T02:47:43.6333333+00:00
LXF 160 Reputation points
answered 2024-06-11T10:06:35.52+00:00
Akshay-MSFT 17,641 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How to find the creation date of each analytical rule on Sentinel

Hi all, I am aiming to find the number of new analytical rules created per month, as well as the existing total per month on Sentinel for the last 2 months and present it to a Sentinel workbook. To achieve this, I am considering REST calls against…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-07T10:28:09.6+00:00
Evangelos Spatharas (CP,UK) 20 Reputation points
commented 2024-06-10T16:17:58.84+00:00
Evangelos Spatharas (CP,UK) 20 Reputation points
1 answer

Sentinel Active Rules

I would like to see the datas about my active rules, for example, I would like to see the Created Date about my rules. I can see only the column "last modified". Can I see this informations using KQL? Obs: I only use the table Security…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-06-05T17:39:53.08+00:00
Hyago Santana Mariano 0 Reputation points
commented 2024-06-10T03:33:35.8333333+00:00
Givary-MSFT 30,251 Reputation points Microsoft Employee
1 answer

Finding classic automation in Sentinel analytics

I have the ability to search through ARM templates for the Sentinel analytics and I'm hoping to find a way to detect the use of classic alert automation. Does anyone know what i should be searching for in the ARM template? We have not used this method,…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-05-15T18:59:30.75+00:00
George Zerphey 136 Reputation points
commented 2024-06-04T20:58:41.6833333+00:00
James Hamil 22,981 Reputation points Microsoft Employee
2 answers

Not allowing to connect Sentinel Data connector with Defender XDR

Hello, I was trying to connect the "Microsoft Defender XDR" connector with "Microsoft Sentinel", but I am facing the below error. I am not sure why Sentinel is not allowing to establish the XDR connector. As I am the Owner of the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
asked 2024-05-08T12:07:43.2433333+00:00
Karan Bhatt 27 Reputation points
commented 2024-06-04T20:50:35.54+00:00
James Hamil 22,981 Reputation points Microsoft Employee
2 answers

Isolate Machine -playbook in Sentinel

Hi, we are trying to create isolate machine Sentinel incident playbook but we only get error message 404 resource not found when running it. Is it possible to use that playbook if machine accounts are synced from on-premise ad or does it need something…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-05-28T13:00:53.6866667+00:00
JukkaV 5 Reputation points
answered 2024-06-04T09:09:40.2333333+00:00
JukkaV 5 Reputation points
1 answer One of the answers was accepted by the question author.

The request type when fetching to S3

Hi all, I would like to connect S3 and microsoft sentinel. I have a question. ・I think you fetch files from microsoft sentinel to S3, is the request type GET? The following is the page to which we…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-05-27T06:40:15.37+00:00
横田 大和 40 Reputation points
accepted 2024-05-30T00:43:17.62+00:00
横田 大和 40 Reputation points
1 answer One of the answers was accepted by the question author.

Moving Sentinel to a different management group

Hey folks, I know that moving Sentinel from one subscription to a different one is not supported and can break things. Could somebody tell me, whether moving a whole subscription that contains a Sentinel instance from one management group to another…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-05-23T12:30:00.3566667+00:00
Sándor Tőkési 181 Reputation points
accepted 2024-05-29T16:45:31.3066667+00:00
Sándor Tőkési 181 Reputation points
0 answers

Sentinel - Sophos Endpoint Protection (using REST API) (Preview) - Fails due to trying to create a table with a hyphen!

When trying to configure and deploy the new Sophos API connector for Sentinel it fails. Looks like it's trying to create a new table called Custom-SophosEPAlerts_CL but tables cannot contain hyphens so needs changing to CustomSophosEPAlerts_CL…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-05-22T09:34:28.36+00:00
James Grant 0 Reputation points
commented 2024-05-28T12:43:58.3066667+00:00
Andrew Blumhardt 9,831 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Threat Intelligence Sharing

Hi all, Is it possible to use threat intelligence from a third party solution with Microsoft sentinel? And if possible, how would you connect them? Custom connectors? regard,

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,042 questions
asked 2024-04-23T14:43:59.2633333+00:00
横田 大和 40 Reputation points
accepted 2024-05-27T06:15:28.9033333+00:00
横田 大和 40 Reputation points