974 questions with Microsoft Sentinel tags

Sort by: Updated
1 answer

I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel

I need guide to configure Solaris v10 devices to forward logs to Azure Sentinel. Can someone please help me with steps\document.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2021-09-10T10:52:29.587+00:00
Singh, Sushmita[Non-Employee] 6 Reputation points
commented 2024-04-10T07:27:26.46+00:00
adewale Yusuf 0 Reputation points
3 answers

Content Hub is missing Solutions

Hello, In the content hub I am only seeing 34 solutions. 24 hours ago I was able to see over 200 solutions. I have Azure Activity data connector installed and configured but in the content hub it says I have 0 installed. When I try to search for a…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-04-04T17:37:32.05+00:00
Owen Finn 0 Reputation points
commented 2024-04-10T07:07:05.9933333+00:00
Shweta Mathur 27,301 Reputation points Microsoft Employee
1 answer

ADX cost estimation

I want to prepare an estimate for ADX with 2TB monthly data.. I checked this link "https://dataexplorer.azure.com/AzureDataExplorerCostEstimator.html " . What should I put in for the field "Estimated Data Compression (x times)" …

Azure Cost Management
Azure Cost Management
A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
2,023 questions
Azure Data Explorer
Azure Data Explorer
An Azure data analytics service for real-time analysis on large volumes of data streaming from sources including applications, websites, and internet of things devices.
479 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2022-02-25T11:04:46.533+00:00
Soumya Banerjee 126 Reputation points
commented 2024-04-09T11:27:08.96+00:00
Kaspar Kwok 0 Reputation points
1 answer

Error Whille setting up SMTP Email V3 connection

Hi Team, I am configuring SMTP connection and getting below error Failed to create connection: { "error": { "code": 502, "source": "logic-apis-easteurope.azure-apim.net", "clientRequestId": "",…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-04-05T11:33:16.4333333+00:00
Disha Bodade 45 Reputation points
edited an answer 2024-04-08T23:21:12.0966667+00:00
Marilee Turscak-MSFT 33,801 Reputation points Microsoft Employee
1 answer

Bulk delete Sentinel Threat Intelligence

I used Workspace Purge Rest API to bulk delete Sentinel threat intelligence. I used the api to remove intelligence from 'ThreatIntelligenceIndicator' table on sentinel but this did not end up deleting them from Sentinel threat intelligence (under Threat…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-04-04T15:08:19.5+00:00
Anchal Singh 0 Reputation points
commented 2024-04-08T12:47:40.98+00:00
Shweta Mathur 27,301 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Microsoft sentinel - Data connector shows disconnected after installing

We recently activated Sentinel to give it a trial run. I set up a separate workspace for Sentinel and installed some data connectors. However, the WAF is still showing as disconnected even after installing and configuring it. We've only got WAF, not…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-04-03T09:28:25.2866667+00:00
Someiah C S 60 Reputation points
accepted 2024-04-04T11:19:43.0166667+00:00
Someiah C S 60 Reputation points
2 answers

Microsoft Sentinel Threat Indicators API - nextLink returns same page

Hello, I have an issue where the nextLink is always returning the first page of the Threat Indicators in Sentinel. I'm using the following API-Uri to retrieve all Threat Indicators in a Sentinel Workspace…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-23T21:12:01.4666667+00:00
Benedict Schmieder 0 Reputation points
answered 2024-04-03T11:27:05.8933333+00:00
Benedict Schmieder 0 Reputation points
0 answers

Query set to run in my Logic App is timing out and failing

Hello everyone. I am trouble shooting an issue with my Logic App in which after an incident triggers, the next step is to run the query and list the results, but this part of the Logic App is what is timing out and failing. When reading the timeout…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,837 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-21T13:17:52.54+00:00
Matthew Agosta 0 Reputation points
edited a comment 2024-04-03T09:27:33.3133333+00:00
Clive Watson 5,711 Reputation points MVP
1 answer

Fortinet Playbook Deployment

Hello, Has anyone managed to create the three playbooks that are part of the solution for Fortinet without issues? I am having several issues with all of…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-15T13:12:51.48+00:00
rob wood 41 Reputation points
commented 2024-04-01T17:26:19.3566667+00:00
Givary-MSFT 27,566 Reputation points Microsoft Employee
1 answer

Adding tenable.io connector to Microsoft Sentinel

I am trying to connect tenable io connector to my Sentinel instance. I have followed the steps and provided the access key and other information requested. I can see in my resource group that everything was successfully deployed with app insight and…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-09T15:00:27.28+00:00
Taiwo Oyewo 21 Reputation points
commented 2024-04-01T12:08:40.56+00:00
Givary-MSFT 27,566 Reputation points Microsoft Employee
1 answer

Can't get my app to show up on Sentinel Content Hub

Hello, I am new to the partner portal. We've submitted our app to the partner portal and its been fully published. However, when I search for it in the Content Hub under Sentinel, I cannot find it. How do I get it so that my app shows up? We've…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-11T17:30:04.44+00:00
Dan White 0 Reputation points
commented 2024-04-01T12:05:48.5066667+00:00
Givary-MSFT 27,566 Reputation points Microsoft Employee
1 answer

When an alert is generated in XDR and then synced to Sentinel

When an alert is generated in XDR and then synced to Sentinel, is it possible to measure the time it takes for the alert to be synced? Is there a query that can be used to measure this time in minutes?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-28T11:16:13.39+00:00
Koonnamchok Klongkaew 140 Reputation points
commented 2024-04-01T09:41:38.8633333+00:00
Shweta Mathur 27,301 Reputation points Microsoft Employee
1 answer

Sentinel Services on Azure Portal Showing Non-Sentinel Enabled Workspaces as Well

I have two Log analytics Workspaces, only one with Sentinel enabled, but both the workspaces are shown on Sentinel page on Azure portal, which makes it confusing. Is this default behaviour or can be switched off?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-25T05:30:32.03+00:00
Gorav Gandhi 1 Reputation point
commented 2024-04-01T08:01:02.1766667+00:00
Shweta Mathur 27,301 Reputation points Microsoft Employee
1 answer

Cisco FTD data connector

Hello, I have a customer that is configuring the CISCO FTD data connector. But they say CISCO FTD documentation shows it support only syslog format.  They would like some clarification on the following questions: I. Clarify whether Cisco FTD supports…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-27T22:50:54.9933333+00:00
DG001 346 Reputation points Microsoft Employee
commented 2024-03-29T19:29:09.8466667+00:00
DG001 346 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Data ingestion for Specific data/ specific time period data in table.

In azure sentinel I can calculate data ingestion for whole table but is there any way through which I can calculate specific size of data. Ex : In azure table how much data ingested in last 1 hour. Something like Search criteria & then…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-28T08:22:59+00:00
94554605 40 Reputation points
commented 2024-03-29T07:02:40.4733333+00:00
Givary-MSFT 27,566 Reputation points Microsoft Employee
2 answers

Customer is migrating Azure from CSP to MCA and they wanted to understand what configurations need to do to the subscription to ensure smooth transition

Customer is migrating Azure from CSP to MCA and they wanted to understand what configurations need to do to the subscription to ensure smooth transition. Also, want to check if there is any impact on tenant, subscription and Log analytical workspace…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2023-05-26T07:23:04.3633333+00:00
Parshuram Tularam Kushwah 0 Reputation points
commented 2024-03-28T14:56:41.7666667+00:00
Justin Venter 80 Reputation points Microsoft Employee
4 answers

Fortinet Connector or CEF AMA Connector? - Sentinel

Hello, Client has Fortinet connector but is having to filter logging so that the log ingestion is not massively costly. I'm sure we could achieve better results using the CEF AMA connector to filter out the security logs from syslog but not sure what to…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-02-29T15:03:56.91+00:00
rob wood 41 Reputation points
answered 2024-03-26T19:39:38.2066667+00:00
Marilee Turscak-MSFT 33,801 Reputation points Microsoft Employee
1 answer

How to optimize amount of data sent via LogsIngestionClient.upload operation

Hi, I am using logs ingestion client in python to upload data. My usecase is to read messages off of aws sqs and build payloads that can be sent via LogsIngestionClient client. I built a simple timer trigger function app that reads aws sqs for new…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
4,232 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-26T01:19:20.7733333+00:00
Ashwin Venkatesha 60 Reputation points
edited the question 2024-03-26T17:51:42.98+00:00
Monalla-MSFT 11,551 Reputation points
2 answers One of the answers was accepted by the question author.

Retention log

Hi all, I would like to know some information about the Sentinel log ingestion pricing. My goal is to increase this period to 1 year. What I read is the possibility not to ingest that log (saving money) but to use the archived period to store these…

Azure Cost Management
Azure Cost Management
A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
2,023 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-12T14:29:02.9133333+00:00
Roberto D'Andrea 20 Reputation points
accepted 2024-03-22T08:26:42.8233333+00:00
Roberto D'Andrea 20 Reputation points
1 answer

Syslog via Legacy Agent Microsoft Sentinel

We have an Ubuntu Azure VM for our log collector for Sentinel. We have had some issues with the syslog via legacy agent as of late, but those have been resolved. (Yes I know this connector is going away, but for now I want it working). We send logs…

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
974 questions
asked 2024-03-20T14:27:59.3366667+00:00
jreece22 0 Reputation points
answered 2024-03-22T07:22:44.7266667+00:00
Akshay-MSFT 16,026 Reputation points Microsoft Employee