Sentinel 'Events and alerts over time' graph

Niall Quinn 1 Reputation point
2020-09-22T15:00:06.283+00:00

Hi all,

Let me start by thanking you in advance and being honest that I am very new to Sentinel.

I've deployed a few Windows Firewall Data Connectors, Over the past few hours. However, the graph under the 'Workspace' for these machines looks odd. ID expected to see these events in a linear format across the various hours and minutes following the Data Connectors being deployed. However its just one massive spike.

Again, I'm as rookie as they come with Sentinel.

Thanks,
Niall

26466-capture.png

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2020-09-24T00:08:57.413+00:00

    The filter is over a 24 hour period and the events are showing up at 2 PM. Is that different from what you would expect? What types of events are these?

    It may take 20 minutes for the full events to show so it's possible that hadn't logged everything by the time when you checked. https://learn.microsoft.com/en-us/azure/sentinel/connect-windows-security-events

    2 people found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.