Sentinel unexpected error

Sebastian Enström 0 Reputation points
2024-09-26T06:28:42.5+00:00

Hi!

I have an issue with Microsoft Sentinel. Every now and then I get this "unexpected error". When this happens all connectors show as not connected, I can't run any queries nor see any logs. I still receive incidents based on some analytic rules I have. So logs is indeed beeing ingested still.
This seem to happen randomly and always solves itself within a day or two. But it is extreamly annoying because it stops our workflow.
We are currently looking at Sentinel for our main SIEM solution, but as it seems to "break" for no reason makes me question it..
We have 12 connectors, most of them Microsoft based (Entra ID, Azure Activity, Defender for Endpoint, Azure Firewall etc) but we also ingest syslogs from on prem firewalls using Common Event Format (CEF) via AMA connector.

Have anyone else experienced similar issues with Sentinel?

BR.

bild

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,141 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.