I have the same issue when accessing the client tenant via CSP. Direct access is working.
Classic CA policies were removed. It's not that.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi!
I have an issue with Microsoft Sentinel. Every now and then I get this "unexpected error". When this happens all connectors show as not connected, I can't run any queries nor see any logs. I still receive incidents based on some analytic rules I have. So logs is indeed beeing ingested still.
This seem to happen randomly and always solves itself within a day or two. But it is extreamly annoying because it stops our workflow.
We are currently looking at Sentinel for our main SIEM solution, but as it seems to "break" for no reason makes me question it..
We have 12 connectors, most of them Microsoft based (Entra ID, Azure Activity, Defender for Endpoint, Azure Firewall etc) but we also ingest syslogs from on prem firewalls using Common Event Format (CEF) via AMA connector.
Have anyone else experienced similar issues with Sentinel?
BR.
I have the same issue when accessing the client tenant via CSP. Direct access is working.
Classic CA policies were removed. It's not that.