1,165 questions with Microsoft Sentinel tags

Sort by: Updated
0 answers

Not receiving windows security event from Azure ARC enabled servers

Successfully connected Windows server through Azure ARC but not receiving any security event logs through data collection rule in Sentinel connector. The AMA extension is showing running successfully.

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,330 questions
Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
440 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,260 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-15T14:13:18.75+00:00
Rahul Saha 0 Reputation points
commented 2024-11-15T21:00:30.7666667+00:00
Pranay Reddy Madireddy 535 Reputation points Microsoft Vendor
0 answers

Difficulty Identifying Edited Rules in Azure Firewall Logs via KQL

Hello, community! I'm having trouble identifying specific changes to Azure Firewall rules through KQL (Kusto Query Language). After modifying certain firewall rules, I can see that edits have occurred through the firewall’s logs tab (where it shows a…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
681 questions
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
94 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-07T14:16:55.0666667+00:00
Hyago Santana Mariano 20 Reputation points
commented 2024-11-15T19:07:16.6333333+00:00
Rohith Vinnakota 1,160 Reputation points Microsoft Vendor
1 answer

Looking for query where we can get the following data from Azure Virtual Desktop under a particular host pool

Looking for query where we can get the following data from Azure Virtual Desktop under a particular host pool. Who has not logged in over the past 30 days For those who have logged in, how many days did they log in What is the amount of time users…

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,582 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,203 questions
asked 2024-11-11T23:53:53.5633333+00:00
Joshua Hensley 21 Reputation points
commented 2024-11-15T01:54:07.1666667+00:00
Mounika Reddy Anumandla 825 Reputation points Microsoft Vendor
1 answer

How to enable Azure Activity Sentinel Data Connector

Hi, I'm trying to enable Azure Activity Sentinel Data Connector. I've manage to install it and when I follow the 'Launch Azure Policy Assignment Wizard' it completes successfully, however the Azure Activity Data Connector never shows 'green/connected'…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-07T12:11:18.33+00:00
Silva, Luis 0 Reputation points
commented 2024-11-15T00:13:21.7866667+00:00
Navya 12,570 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Using Logic Apps across multiple tenants

I am planning to onboard another tenant to my setup and considering using Lighthouse. My goal is to manage Microsoft Sentinel and create logic apps in one tenant while using them for automation in a different tenant. Could someone assist me with setting…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,221 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2023-12-17T11:46:58.88+00:00
Cloudsec 160 Reputation points
edited a comment 2024-11-14T18:56:55.6633333+00:00
Andy Nicholls 0 Reputation points
1 answer

Sentinel Smart Deployment cannot push csv file to Azure DevOps

When I deploy content to sentinel using Azure DevOps, the content deploys successfully but when smart deployment enabled, it cannot push csv tracking file to Azure Repo with error [Warning] API call failed:…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-04-05T06:33:36.0033333+00:00
Ha Nguyen 10 Reputation points
commented 2024-11-14T14:04:33.61+00:00
Torstein Lundervold Nesheim 0 Reputation points
1 answer

Update to Python 3.11 got SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)')))

Hi, After we updated our Sentinel data connector(implemented in Azure Function) to use python3.11 from 3.10, we got SSL Error from urllib3 when making API calls: SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
5,137 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-09-24T17:10:13.2266667+00:00
Xiuyang Bobby Sun 65 Reputation points
answered 2024-11-14T10:00:01.8433333+00:00
Pauline Mbabu 560 Reputation points Microsoft Employee
0 answers

Can we send Defender for Cloud's logs to Sentinel's LAW without "Defender for cloud connector" configured in Sentinel?

Question: While deploying Defender for Cloud, if we select the same LAW (workspace) that Sentinel is using, do we still need to configure Defender for Cloud connector and configure it in Sentinel? In this scenario, do Defender for Cloud and Sentinel's…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,420 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-12T14:28:00.0966667+00:00
Rakesh Singh 250 Reputation points
commented 2024-11-14T02:28:15.29+00:00
Navya 12,570 Reputation points Microsoft Vendor
1 answer

logic App to ingest notification of azure monitor alerte to Microsoft sentinel

Hi, In the alert rule configuration for Azure Monitoring, I need to set up an action group (Logic App) that will forward all alert notifications to Microsoft Sentinel. However, I require assistance with designing a Logic App that meets my needs, as I'm…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,221 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-08T17:44:51.8966667+00:00
Dhahri, Arwa 0 Reputation points
commented 2024-11-13T19:18:33.3466667+00:00
LeelaRajeshSayana-MSFT 16,281 Reputation points
1 answer

How to export piechart from MS Defender XDR Advanced Hunting?

Hello everyone, I am trying to export query result as a piechart, but there is no such an option. Do I miss something or is impossible? Thanks! Aleksandar

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,166 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
212 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
150 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
48 questions
asked 2024-11-12T09:51:02.8+00:00
Aleksandar Tomov 30 Reputation points
answered 2024-11-13T00:25:38.94+00:00
James Hamil 25,636 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

How to do a recursive function with KQL

I have table in Sentinel for all employees. Each lines has an name, employee ID and a direct supervisor ID. I want to be able to give the supervisor ID, and from there, have a recursive loop that will verify all employee who has that supervisor as a…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-01T19:34:43.5533333+00:00
GuyP Dubois 20 Reputation points
accepted 2024-11-12T15:10:25.5166667+00:00
GuyP Dubois 20 Reputation points
1 answer

Sentinel - Summary rules doesn't send triggered events to destination

I have been exploring summary rules, created a summary rule that has a KQL. Source is one of my custom table that has some logs I want to trigger via summary rules and ingest in a custom analytic table. When I try to simulate the KQL query it shows me…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-08T12:45:25.03+00:00
Khanna, Keshav 0 Reputation points
commented 2024-11-12T14:42:00.3966667+00:00
Raja Pothuraju 8,095 Reputation points Microsoft Vendor
1 answer

What is the application "Office 365 Management" (AppId 00b41c95-dab0-4487-9791-b9d2c32c80f2) and why is Conditional Access not applied to it?

I am investigating a security incident and I have identified entries in the MS Sentinel SigninLogs table that might be related to the breach with the attributes: AppDisplayName: Office 365 Management AppId:…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-07T16:22:56.1666667+00:00
Tilman Schmidt 0 Reputation points
commented 2024-11-12T09:11:32.76+00:00
BANDELA Siri Chandana 245 Reputation points Microsoft Vendor
1 answer

How can I configure Microsoft Sentinel to create a new incident instead of adding to an existing one?

I'm facing an issue in Microsoft Sentinel where incidents generated by an analytics rule are automatically closing and merging with an existing "multiple-stage" incident. As shown in the attached screenshot, each new incident created by the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-10-29T05:26:13.2566667+00:00
mara7 166 Reputation points
commented 2024-11-12T00:02:02.5566667+00:00
mara7 166 Reputation points
2 answers

Cannot enable UEBA feature on Sentinel

Hi, I'm having some issues while trying to enable the UEBA feature in a Sentinel instance. When I try to turn the switch ON, I get the following error message: "Updating the Entity Providers failed". I've seen 2 questions related to this…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-06T12:02:39.82+00:00
Alberto Barrado Jiménez 5 Reputation points
answered 2024-11-11T19:41:57.87+00:00
Andrew Blumhardt 9,866 Reputation points Microsoft Employee
1 answer

'updating the entity providers failed'. microsoft sentinal

I'm having some issues while enabling the UEBA feature in a Sentinel instance. When I try to turn the switch ON, I get the following error message: "Updating the Entity Providers failed". i am trying this with a global admin account but still…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,203 questions
asked 2024-11-11T12:33:58.0366667+00:00
Hain Joseph 0 Reputation points
answered 2024-11-11T19:15:27.54+00:00
James Hamil 25,636 Reputation points Microsoft Employee
0 answers

How to find existing data connectors of Azure logic app workflow

Hello Team, We are facing issue with existing data connector in Microsoft Sentinel Playbook. We are unable to find the existing data connector at our end. Please help. Thank You.

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,221 questions
Office Development
Office Development
Office: A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.Development: The process of researching, productizing, and refining new or existing technologies.
4,006 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-11T15:44:45.08+00:00
Bharat Debhade 0 Reputation points
commented 2024-11-11T16:36:59.91+00:00
Clive Watson 6,601 Reputation points MVP
1 answer

Cant Import Sentinel Alert Rules

Good morning, I am having difficulty importing sentinel rules after I deleted old ones. I deleted the old rules on friday 9/27 9am EST and am getting the error the rule with ID 'xyz' was recently deleted. You need to allow some time before re-using the…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-09-30T13:22:40.92+00:00
Eugene Golovanyuk 40 Reputation points
commented 2024-11-07T18:19:18.3966667+00:00
Igor Guarisma 0 Reputation points
1 answer One of the answers was accepted by the question author.

Sentinel duplicate alerts and incidents

In sentinel We have an alert "User Assigned Privileged Role" and it repeats every hour for a day or two. How do I stop it repeating itself. The rule itself triggers when an administrator changes permissions for another user (or themselves)…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-06T15:31:49.9433333+00:00
Son man 20 Reputation points
accepted 2024-11-07T13:29:36.64+00:00
Son man 20 Reputation points
2 answers

How to Upload Carbon Black Logs and Alerts into Azure Sentinel for Evaluation

I am trying to evaluate how much Azure Sentinel helps my business's security needs. I am particularly interested in seeing how well Azure Sentinel can cluster alerts together. I have taken a small amount of EDR logs and alerts (which are in json format)…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,234 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,165 questions
asked 2024-11-05T17:55:49.1566667+00:00
psec-comp 0 Reputation points
answered 2024-11-06T12:12:44.0266667+00:00
Andrew Blumhardt 9,866 Reputation points Microsoft Employee